Svchost

Résolu
Bonjour,

je viens vers vous car lorsque j'ai ctrl+supp j'ai 9 svchost.exe
lorsque je regarde sur le net je lis soit que c'est un element de win xp soit que cest un virus

si quelqu'un pouvait m'aider en me fesant faire les manip comme vous savez bien les faire et les comprendre !!

en + mon ordi rame a fond en ce moment

merci d'avance pour votre aide
Configuration: Windows XP
Firefox 3.5.5

47 réponses

Résumé de la discussion

La problématique porte sur la présence de plusieurs svchost.exe sous Windows XP et l’éventualité d’un virus lorsque le système rame et les indications d’éléments suspects dans les processus système. Des éléments de réponse essentiels évoquent des vérifications classiques, notamment la vérification des emplacements des svchost, l’examen des rapports de sécurité et l’usage d’outils comme UsbFix ou HijackThis pour la désinfection. Les échanges montrent aussi des observations pratiques, telles que la présence d’un processus Avast/Avira, la liste des fichiers et des exécutables, et la nécessité de poursuivre les scans jusqu’à nettoyage complet. En parallèle, des détails techniques sur les rapports et les dossiers supprimés sont fournis, ainsi que des éléments suspects mais non conclusifs, rappelant qu’aucune synthèse finale n’est donnée.

Bobot (l’IA à votre service)
  1. j'ai tjr autant de svchost

    mais pour le moment ca a l'air d'aller

    merci de ton aide et de ta patience
    1. j'ai supprime tous les jeux et films pour refaire un test

      que dois je refaire ?

      merci
      1. [b]SDFix: Version 1.240 [/b]
        Run by DEMANGEOT SolŠne on 27/11/2009 at 10:55

        Microsoft Windows XP [version 5.1.2600]
        Running From: C:\SDFix

        [b]Checking Services [/b]:

        Restoring Default Security Values
        Restoring Default Hosts File

        Rebooting

        [b]Checking Files [/b]:

        No Trojan Files Found

        Removing Temp Files

        [b]ADS Check [/b]:

        [b]Final Check [/b]:

        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-11-27 12:13:30
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ...

        scanning hidden services & system hive ...

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
        "s1"=dword:3f7bb057
        "s2"=dword:384d24af
        "h0"=dword:00000003

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
        "h0"=dword:00000000
        "ujdew"=hex:0e,d5,52,81,99,25,08,1f,d8,9d,d5,2d,01,6b,6c,f5,32,95,63,20,8f,..

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
        "h0"=dword:00000002
        "hdf12"=hex:36,d0,cb,ab,82,71,17,49,24,41,ce,c7,86,cf,90,f8,bc,06,b3,f2,b9,..
        "p0"="C:\Program Files\DAEMON Tools Lite\"

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
        "a0"=hex:20,01,00,00,07,c4,29,1d,da,6f,ae,74,93,56,f1,f8,99,00,64,3f,d9,..
        "hdf12"=hex:ec,93,a2,5c,d1,84,59,7b,5c,d1,d4,f5,47,c6,50,75,62,bf,eb,a7,97,..

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
        "hdf12"=hex:1f,9f,e6,a6,7e,2e,63,9f,ad,48,fe,a6,37,29,74,2f,68,f6,d0,20,dc,..

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
        "h0"=dword:00000001
        "khjeh"=hex:e3,dd,c6,11,05,56,83,b2,8f,18,67,8a,ef,9b,d5,5a,86,fd,0f,14,a1,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
        "h0"=dword:00000000
        "ujdew"=hex:0e,d5,52,81,99,25,08,1f,d8,9d,d5,2d,01,6b,6c,f5,32,95,63,20,8f,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
        "h0"=dword:00000001
        "khjeh"=hex:e3,dd,c6,11,05,56,83,b2,8f,18,67,8a,ef,9b,d5,5a,86,fd,0f,14,a1,..
        "p0"="C:\Program Files\DAEMON Tools\"

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
        "a0"=hex:20,01,00,00,f3,13,98,e1,08,f5,c3,77,ff,f7,21,01,45,82,f7,a9,b5,..
        "khjeh"=hex:e6,7d,9f,c9,95,86,ed,54,ea,cf,1d,07,a5,4c,ce,46,cc,89,2a,44,c8,..

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
        "khjeh"=hex:a3,d0,06,7b,4f,58,3c,ff,5a,44,37,95,b5,44,83,1c,2b,4c,ed,38,55,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
        "h0"=dword:00000000
        "ujdew"=hex:0e,d5,52,81,99,25,08,1f,d8,9d,d5,2d,01,6b,6c,f5,32,95,63,20,8f,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
        "h0"=dword:00000002
        "hdf12"=hex:36,d0,cb,ab,82,71,17,49,24,41,ce,c7,86,cf,90,f8,bc,06,b3,f2,b9,..
        "p0"="C:\Program Files\DAEMON Tools Lite\"

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
        "a0"=hex:20,01,00,00,07,c4,29,1d,da,6f,ae,74,93,56,f1,f8,99,00,64,3f,d9,..
        "hdf12"=hex:ec,93,a2,5c,d1,84,59,7b,5c,d1,d4,f5,47,c6,50,75,62,bf,eb,a7,97,..

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
        "hdf12"=hex:1f,9f,e6,a6,7e,2e,63,9f,ad,48,fe,a6,37,29,74,2f,68,f6,d0,20,dc,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
        "h0"=dword:00000001
        "khjeh"=hex:e3,dd,c6,11,05,56,83,b2,8f,18,67,8a,ef,9b,d5,5a,86,fd,0f,14,a1,..

        scanning hidden registry entries ...

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        [b]Remaining Services [/b]:

        Authorized Application Key Export:

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
        "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
        "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"="C:\\Program Files\\Freeplayer\\vlc\\vlc.exe:*:Enabled:VLC media player"
        "C:\\WINDOWS\\Temp\\NavBrowser.exe"="C:\\WINDOWS\\Temp\\NavBrowser.exe:*:Enabled:NAVBrowser"
        "C:\\Program Files\\FileZilla\\FileZilla.exe"="C:\\Program Files\\FileZilla\\FileZilla.exe:*:Enabled:FileZilla"
        "C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\56ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\56ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\74ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\74ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\11ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\11ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\32ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\32ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\87ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\87ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\63ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\63ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\14ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\14ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\43ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\43ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\5ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\5ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\98ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\98ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\1ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\1ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\12ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\12ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\90ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\90ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\52ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\52ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\93ex3.modul32.exe"="C:\\DOCUME~1\\DEMANG~1\\LOCALS~1\\Temp\\93ex3.modul32.exe:*:Enabled:Microsoft Update"
        "C:\\Program Files\\Messenger\\Msmsgs.exe"="C:\\Program Files\\Messenger\\Msmsgs.exe:*:Enabled:Windows Messenger"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\TribalWeb.net\\tribalweb.exe"="C:\\Program Files\\TribalWeb.net\\tribalweb.exe:*:Enabled:TribalWeb.net : R‚seau priv‚ sur Internet"
        "C:\\Program Files\\BitDownload\\BitDownload.exe"="C:\\Program Files\\BitDownload\\BitDownload.exe:*:Enabled:Torrent P2P application"
        "C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:Partage de l'application RTC"
        "C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows© NetMeeting©"
        "C:\\Program Files\\WINSOS\\winsos.exe"="C:\\Program Files\\Winsos\\winsos.exe:*:Enabled:Winsos"
        "C:\\Program Files\\WINSOS\\anti-spy.exe"="C:\\Program Files\\Winsos\\anti-spy.exe:*:Enabled:anti-spy Winsos"
        "C:\\Program Files\\WINSOS\\help.exe"="C:\\Program Files\\Winsos\\help.exe:*:Enabled:Winsos Help"
        "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
        "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
        "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
        "C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
        "C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Enabled:Microsoft Management Console"
        "C:\\Program Files\\GigaTribe\\gigatribe.exe"="C:\\Program Files\\GigaTribe\\gigatribe.exe:*:Enabled:gigatribe"
        "D:\\eSKernel.exe"="D:\\eSKernel.exe:*:Enabled:Bbox assistant d'installation"
        "C:\\Program Files\\Vuze\\Azureus.exe"="C:\\Program Files\\Vuze\\Azureus.exe:*:Enabled:Azureus"
        "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
        "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
        "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
        "C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"="C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe:*:Enabled:Skype Extras Manager"
        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
        "C:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"="C:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe:*:Enabled:Logitech Vid"
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
        "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"

        [b]Remaining Files [/b]:

        [b]Files with Hidden Attributes [/b]:

        Fri 2 May 2008 1,996,104 ...H. --- "C:\Program Files\5 Realms of Cards\Realms.exe"
        Thu 19 Nov 2009 3,790,160 ...H. --- "C:\Program Files\Dairy Dash\dairydash.exe"
        Wed 27 Aug 2008 1,103,176 ...H. --- "C:\Program Files\Empire of the Gods\Empire of the Gods.exe"
        Thu 10 Jan 2008 7,341,384 ...H. --- "C:\Program Files\Five Card Deluxe\fivecarddeluxe.exe"
        Mon 13 Apr 2009 2,176,336 ...H. --- "C:\Program Files\Gunslinger Solitaire\GunslingerSolitaireLowRes.exe"
        Thu 19 Nov 2009 26,346,832 ...H. --- "C:\Program Files\Ice Blast\Iceblast_FR_05.exe"
        Mon 24 Aug 2009 26,764,624 ...H. --- "C:\Program Files\John and Mary's Memories\memories.exe"
        Thu 11 Sep 2008 12,158,280 ...H. --- "C:\Program Files\Poker Pop\pokerpop.exe"
        Thu 19 Nov 2009 2,835,792 ...H. --- "C:\Program Files\World of Zellians - Kingdom Builder\World of Zellians.exe"
        Sat 30 Dec 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
        Tue 2 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
        Sun 30 Aug 2009 165,232 A..H. --- "C:\Documents and Settings\DEMANGEOT SolŠne\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll"
        Fri 17 Jul 2009 21,135 ...HR --- "C:\Documents and Settings\DEMANGEOT SolŠne\Application Data\SecuROM\UserData\securom_v7_01.bak"

        [b]Finished![/b]
        1. Contributeur sécurité
          Bonsoir,

          désactive Antivir le temps de passer SDfix ;)
          1. Contributeur sécurité
            Bonjour,

            pour vérifier, fais ceci stp :

            ▶ Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

            ▶ Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.

            /!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..

            Comment redémarrer en mode sans échec ??

            ▶ Choisir son compte, pas celui de l'Administrateur ou autre.

            Dérouler la liste des instructions ci-dessous :

            • Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
            • Appuyer sur Y pour commencer le processus de nettoyage.
            • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
            • Appuyer sur une touche pour redémarrer le PC.
            • Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
            • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
            • Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
            • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
            • Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
            1. merci de votre aide
              j'ai toujours des fichiers bizarre dans le gestionnaires des taches comme alg.exe pou alq.exe ou encore 8 svchost
              1. Contributeur sécurité
                Ok... Est-ce que tu as encore des problèmes ??
                1. Contributeur sécurité
                  Je vois que tu es un acharné du P2P lol

                  A lire : https://forum.malekal.com/viewtopic.php?t=3208&start=

                  Rends-toi à ce chemin : C:\Program Files\Trend Micro\HijackThis\DEMANGEOT Solène.exe

                  et double-clique sur DEMANGEOT Solène.exe

                  Choisi "Do a system scan only" et coches ces lignes stp :

                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  R3 - URLSearchHook: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
                  O2 - BHO: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
                  O3 - Toolbar: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: (no name) - {cd36797a-70f3-4acd-8825-623d3b896881} - (no file)
                  O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} -
                  O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} -
                  O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

                  puis tu cliques sur Fix checked.

                  ensuite :

                  Rends-toi dans ajout/suppression de programmes et désinstalle toutes les version de Java.

                  Ensuite télécharge la dernière version : https://www.java.com/fr/download/

                  Ensuite :

                  Rends-toi encore une fois dans ajout/suppression de programmes et désinstalle toutes les version d'Adobe Reader.

                  Ensuite télécharge la dernière version : https://get2.adobe.com/fr/reader/otherversions/

                  Décoches la case pour installer McAfee Security Scan

                  Ensuite :

                  ▶ Télécharge CCleaner

                  ▶ Tu auras un tutoriel pour l'installer et l'utiliser correctement.

                  ▶ Fais le nettoyage et recherche les erreurs du registre comme expliqué en bas du tutoriel.

                  Ensuite reviens signaler quand tout sera fait stp
                  1. Logfile of random's system information tool 1.06 (written by random/random)
                    Run by DEMANGEOT Solène at 2009-11-24 11:48:59
                    Microsoft Windows XP Édition familiale Service Pack 3
                    System drive C: has 181 GB (76%) free of 238 GB
                    Total RAM: 1023 MB (53% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 11:49:14, on 24/11/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16915)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                    C:\Program Files\Fichiers communs\alq.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Java\jre6\bin\jucheck.exe
                    C:\Program Files\Windows Live\Contacts\wlcomm.exe
                    C:\Program Files\uTorrent\uTorrent.exe
                    C:\Program Files\Outlook Express\msimn.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Documents and Settings\DEMANGEOT Solène\Mes documents\Téléchargements\RSIT.exe
                    C:\Program Files\Trend Micro\HijackThis\DEMANGEOT Solène.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                    R3 - URLSearchHook: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
                    O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: (no name) - {cd36797a-70f3-4acd-8825-623d3b896881} - (no file)
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O3 - Toolbar: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbSha1.dll
                    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                    O4 - HKLM\..\Run: [Application Layer Gateway] C:\Program Files\Fichiers communs\alq.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
                    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
                    O4 - Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} -
                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by115w.bay115.mail.live.com/mail/resources/MsnPUpld.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                    O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://games.bigfishgames.com/fr_bigcityadventuresa/online/JBGamePlayer.cab
                    O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.6.0_01) -
                    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} -
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
                    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                    1. Contributeur sécurité
                      Et il ne trouve plus dans la liste de tes programmes ??
                      1. bonjour,

                        le seul BitDownload que je trouve se situe : C:\Lop SD\Backup-Lop\DOCUME~1\DEMANG~1\APPLIC~1

                        merci
                        1. Contributeur sécurité
                          Bonjour,

                          pourrais-tu aller vérifier si tu as encore ce dossier mis en gras dans tes programmes ??

                          C:\Program Files\BitDownload
                          1. All processes killed
                            ========== FILES ==========
                            File/Folder C:\Program Files\BitDownload not found.
                            ========== COMMANDS ==========

                            [EMPTYTEMP]

                            User: All Users

                            User: Default User
                            ->Temp folder emptied: 0 bytes
                            ->Temporary Internet Files folder emptied: 33170 bytes

                            User: DEMANGEOT Solène
                            ->Temp folder emptied: 475335711 bytes
                            ->Temporary Internet Files folder emptied: 7881227 bytes
                            ->Java cache emptied: 13689500 bytes
                            ->FireFox cache emptied: 103516079 bytes

                            User: DEMANGEOT Sol�ne

                            User: LocalService
                            ->Temp folder emptied: 66016 bytes
                            ->Temporary Internet Files folder emptied: 33170 bytes

                            User: NetworkService
                            ->Temp folder emptied: 0 bytes
                            ->Temporary Internet Files folder emptied: 73104199 bytes

                            %systemdrive% .tmp files removed: 0 bytes
                            %systemroot% .tmp files removed: 2672076 bytes
                            %systemroot%\System32 .tmp files removed: 4371456 bytes
                            Windows Temp folder emptied: 742131 bytes
                            %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 10943062 bytes
                            %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                            RecycleBin emptied: 4253617590 bytes

                            Total Files Cleaned = 620,91 mb

                            OTM by OldTimer - Version 3.1.2.0 log created on 11232009_112426
                            1. Contributeur sécurité
                              /!\ Procédure strictement réservée à suhelen /!\

                              Pour les visiteurs de ce sujet ayant le même problème : NE PAS EXECUTER CETTE PROCEDURE !!


                              ▶ Télécharge OTM (de Old_Timer) sur ton Bureau

                              ▶ Double-clique sur OTM.exe pour le lancer.

                              ▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous "Paste instructions for item to be moved".

                              :files
                              C:\Program Files\BitDownload

                              :commands
                              [emptytemp]
                              [reboot]


                              ▶ clique sur MoveIt! puis ferme OTM.

                              ▶ Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.

                              ▶ Accepte en cliquant sur YES.

                              ▶ Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                              ▶ Le nom du rapport correspond au moment de sa création : date_heure.log

                              • 1
                              • 2
                              • 3