Svchost
Résoluje viens vers vous car lorsque j'ai ctrl+supp j'ai 9 svchost.exe
lorsque je regarde sur le net je lis soit que c'est un element de win xp soit que cest un virus
si quelqu'un pouvait m'aider en me fesant faire les manip comme vous savez bien les faire et les comprendre !!
en + mon ordi rame a fond en ce moment
merci d'avance pour votre aide
Configuration: Windows XP Firefox 3.5.5
47 réponses
La problématique porte sur la présence de plusieurs svchost.exe sous Windows XP et l’éventualité d’un virus lorsque le système rame et les indications d’éléments suspects dans les processus système. Des éléments de réponse essentiels évoquent des vérifications classiques, notamment la vérification des emplacements des svchost, l’examen des rapports de sécurité et l’usage d’outils comme UsbFix ou HijackThis pour la désinfection. Les échanges montrent aussi des observations pratiques, telles que la présence d’un processus Avast/Avira, la liste des fichiers et des exécutables, et la nécessité de poursuivre les scans jusqu’à nettoyage complet. En parallèle, des détails techniques sur les rapports et les dossiers supprimés sont fournis, ainsi que des éléments suspects mais non conclusifs, rappelant qu’aucune synthèse finale n’est donnée.
-
j'ai tjr autant de svchost
mais pour le moment ca a l'air d'aller
merci de ton aide et de ta patience -
Contributeur sécuritéBonsoir,
as-tu encore des soucis ?? -
j'ai supprime tous les jeux et films pour refaire un test
que dois je refaire ?
merci -
[b]SDFix: Version 1.240 [/b]
Run by DEMANGEOT SolŠne on 27/11/2009 at 10:55
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-27 12:13:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:3f7bb057
"s2"=dword:384d24af
"h0"=dword:00000003
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:0e,d5,52,81,99,25,08,1f,d8,9d,d5,2d,01,6b,6c,f5,32,95,63,20,8f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000002
"hdf12"=hex:36,d0,cb,ab,82,71,17,49,24,41,ce,c7,86,cf,90,f8,bc,06,b3,f2,b9,..
"p0"="C:\Program Files\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,07,c4,29,1d,da,6f,ae,74,93,56,f1,f8,99,00,64,3f,d9,..
"hdf12"=hex:ec,93,a2,5c,d1,84,59,7b,5c,d1,d4,f5,47,c6,50,75,62,bf,eb,a7,97,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:1f,9f,e6,a6,7e,2e,63,9f,ad,48,fe,a6,37,29,74,2f,68,f6,d0,20,dc,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:e3,dd,c6,11,05,56,83,b2,8f,18,67,8a,ef,9b,d5,5a,86,fd,0f,14,a1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:0e,d5,52,81,99,25,08,1f,d8,9d,d5,2d,01,6b,6c,f5,32,95,63,20,8f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:e3,dd,c6,11,05,56,83,b2,8f,18,67,8a,ef,9b,d5,5a,86,fd,0f,14,a1,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,f3,13,98,e1,08,f5,c3,77,ff,f7,21,01,45,82,f7,a9,b5,..
"khjeh"=hex:e6,7d,9f,c9,95,86,ed,54,ea,cf,1d,07,a5,4c,ce,46,cc,89,2a,44,c8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:a3,d0,06,7b,4f,58,3c,ff,5a,44,37,95,b5,44,83,1c,2b,4c,ed,38,55,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:0e,d5,52,81,99,25,08,1f,d8,9d,d5,2d,01,6b,6c,f5,32,95,63,20,8f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000002
"hdf12"=hex:36,d0,cb,ab,82,71,17,49,24,41,ce,c7,86,cf,90,f8,bc,06,b3,f2,b9,..
"p0"="C:\Program Files\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,07,c4,29,1d,da,6f,ae,74,93,56,f1,f8,99,00,64,3f,d9,..
"hdf12"=hex:ec,93,a2,5c,d1,84,59,7b,5c,d1,d4,f5,47,c6,50,75,62,bf,eb,a7,97,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:1f,9f,e6,a6,7e,2e,63,9f,ad,48,fe,a6,37,29,74,2f,68,f6,d0,20,dc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:e3,dd,c6,11,05,56,83,b2,8f,18,67,8a,ef,9b,d5,5a,86,fd,0f,14,a1,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"="C:\\Program Files\\Freeplayer\\vlc\\vlc.exe:*:Enabled:VLC media player"
"C:\\WINDOWS\\Temp\\NavBrowser.exe"="C:\\WINDOWS\\Temp\\NavBrowser.exe:*:Enabled:NAVBrowser"
"C:\\Program Files\\FileZilla\\FileZilla.exe"="C:\\Program Files\\FileZilla\\FileZilla.exe:*:Enabled:FileZilla"
"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\56ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\56ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\74ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\74ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\11ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\11ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\32ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\32ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\87ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\87ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\63ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\63ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\14ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\14ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\43ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\43ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\5ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\5ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\98ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\98ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\1ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\1ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\12ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\12ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\90ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\90ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\52ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\52ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\93ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\93ex3.modul32.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\Messenger\\Msmsgs.exe"="C:\\Program Files\\Messenger\\Msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\TribalWeb.net\\tribalweb.exe"="C:\\Program Files\\TribalWeb.net\\tribalweb.exe:*:Enabled:TribalWeb.net : R‚seau priv‚ sur Internet"
"C:\\Program Files\\BitDownload\\BitDownload.exe"="C:\\Program Files\\BitDownload\\BitDownload.exe:*:Enabled:Torrent P2P application"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:Partage de l'application RTC"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows© NetMeeting©"
"C:\\Program Files\\WINSOS\\winsos.exe"="C:\\Program Files\\Winsos\\winsos.exe:*:Enabled:Winsos"
"C:\\Program Files\\WINSOS\\anti-spy.exe"="C:\\Program Files\\Winsos\\anti-spy.exe:*:Enabled:anti-spy Winsos"
"C:\\Program Files\\WINSOS\\help.exe"="C:\\Program Files\\Winsos\\help.exe:*:Enabled:Winsos Help"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
"C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\\Program Files\\GigaTribe\\gigatribe.exe"="C:\\Program Files\\GigaTribe\\gigatribe.exe:*:Enabled:gigatribe"
"D:\\eSKernel.exe"="D:\\eSKernel.exe:*:Enabled:Bbox assistant d'installation"
"C:\\Program Files\\Vuze\\Azureus.exe"="C:\\Program Files\\Vuze\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"="C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"="C:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe:*:Enabled:Logitech Vid"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
[b]Remaining Files [/b]:
[b]Files with Hidden Attributes [/b]:
Fri 2 May 2008 1,996,104 ...H. --- "C:\Program Files\5 Realms of Cards\Realms.exe"
Thu 19 Nov 2009 3,790,160 ...H. --- "C:\Program Files\Dairy Dash\dairydash.exe"
Wed 27 Aug 2008 1,103,176 ...H. --- "C:\Program Files\Empire of the Gods\Empire of the Gods.exe"
Thu 10 Jan 2008 7,341,384 ...H. --- "C:\Program Files\Five Card Deluxe\fivecarddeluxe.exe"
Mon 13 Apr 2009 2,176,336 ...H. --- "C:\Program Files\Gunslinger Solitaire\GunslingerSolitaireLowRes.exe"
Thu 19 Nov 2009 26,346,832 ...H. --- "C:\Program Files\Ice Blast\Iceblast_FR_05.exe"
Mon 24 Aug 2009 26,764,624 ...H. --- "C:\Program Files\John and Mary's Memories\memories.exe"
Thu 11 Sep 2008 12,158,280 ...H. --- "C:\Program Files\Poker Pop\pokerpop.exe"
Thu 19 Nov 2009 2,835,792 ...H. --- "C:\Program Files\World of Zellians - Kingdom Builder\World of Zellians.exe"
Sat 30 Dec 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 2 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sun 30 Aug 2009 165,232 A..H. --- "C:\Documents and Settings\DEMANGEOT SolŠne\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll"
Fri 17 Jul 2009 21,135 ...HR --- "C:\Documents and Settings\DEMANGEOT SolŠne\Application Data\SecuROM\UserData\securom_v7_01.bak"
[b]Finished![/b] -
Bonjour,
Juste pour suivre le sujet. -
Contributeur sécuritéBonsoir,
désactive Antivir le temps de passer SDfix ;) -
antivir me bloque sdfix
-
Contributeur sécuritéBonjour,
pour vérifier, fais ceci stp :
▶ Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
▶ Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.
/!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..
Comment redémarrer en mode sans échec ??
▶ Choisir son compte, pas celui de l'Administrateur ou autre.
Dérouler la liste des instructions ci-dessous :
• Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuyer sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuyer sur une touche pour redémarrer le PC.
• Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum -
merci de votre aide
j'ai toujours des fichiers bizarre dans le gestionnaires des taches comme alg.exe pou alq.exe ou encore 8 svchost -
Contributeur sécuritéOk... Est-ce que tu as encore des problèmes ??
-
terminé
-
Contributeur sécuritéJe vois que tu es un acharné du P2P lol
A lire : https://forum.malekal.com/viewtopic.php?t=3208&start=
Rends-toi à ce chemin : C:\Program Files\Trend Micro\HijackThis\DEMANGEOT Solène.exe
et double-clique sur DEMANGEOT Solène.exe
Choisi "Do a system scan only" et coches ces lignes stp :
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
O2 - BHO: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
O3 - Toolbar: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {cd36797a-70f3-4acd-8825-623d3b896881} - (no file)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} -
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
puis tu cliques sur Fix checked.
ensuite :
Rends-toi dans ajout/suppression de programmes et désinstalle toutes les version de Java.
Ensuite télécharge la dernière version : https://www.java.com/fr/download/
Ensuite :
Rends-toi encore une fois dans ajout/suppression de programmes et désinstalle toutes les version d'Adobe Reader.
Ensuite télécharge la dernière version : https://get2.adobe.com/fr/reader/otherversions/
Décoches la case pour installer McAfee Security Scan
Ensuite :
▶ Télécharge CCleaner
▶ Tu auras un tutoriel pour l'installer et l'utiliser correctement.
▶ Fais le nettoyage et recherche les erreurs du registre comme expliqué en bas du tutoriel.
Ensuite reviens signaler quand tout sera fait stp -
Logfile of random's system information tool 1.06 (written by random/random)
Run by DEMANGEOT Solène at 2009-11-24 11:48:59
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 181 GB (76%) free of 238 GB
Total RAM: 1023 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:14, on 24/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Fichiers communs\alq.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\DEMANGEOT Solène\Mes documents\Téléchargements\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\DEMANGEOT Solène.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {cd36797a-70f3-4acd-8825-623d3b896881} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Application Layer Gateway] C:\Program Files\Fichiers communs\alq.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
O4 - Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by115w.bay115.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://games.bigfishgames.com/fr_bigcityadventuresa/online/JBGamePlayer.cab
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
-
Contributeur sécuritéOk... Refais un nouveau rapport RSIT stp
-
je ne le voit nul part
-
Contributeur sécuritéEt il ne trouve plus dans la liste de tes programmes ??
-
bonjour,
le seul BitDownload que je trouve se situe : C:\Lop SD\Backup-Lop\DOCUME~1\DEMANG~1\APPLIC~1
merci -
Contributeur sécuritéBonjour,
pourrais-tu aller vérifier si tu as encore ce dossier mis en gras dans tes programmes ??
C:\Program Files\BitDownload -
All processes killed
========== FILES ==========
File/Folder C:\Program Files\BitDownload not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: DEMANGEOT Solène
->Temp folder emptied: 475335711 bytes
->Temporary Internet Files folder emptied: 7881227 bytes
->Java cache emptied: 13689500 bytes
->FireFox cache emptied: 103516079 bytes
User: DEMANGEOT Sol�ne
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 73104199 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2672076 bytes
%systemroot%\System32 .tmp files removed: 4371456 bytes
Windows Temp folder emptied: 742131 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 10943062 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4253617590 bytes
Total Files Cleaned = 620,91 mb
OTM by OldTimer - Version 3.1.2.0 log created on 11232009_112426 -
Contributeur sécurité/!\ Procédure strictement réservée à suhelen /!\
Pour les visiteurs de ce sujet ayant le même problème : NE PAS EXECUTER CETTE PROCEDURE !!
▶ Télécharge OTM (de Old_Timer) sur ton Bureau
▶ Double-clique sur OTM.exe pour le lancer.
▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous "Paste instructions for item to be moved".
:files
C:\Program Files\BitDownload
:commands
[emptytemp]
[reboot]
▶ clique sur MoveIt! puis ferme OTM.
▶ Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
▶ Accepte en cliquant sur YES.
▶ Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
▶ Le nom du rapport correspond au moment de sa création : date_heure.log
- 1
- 2
- 3