CPU a 100%, ordinateur ralenti

Résolu
Bonjour,

voilà tout est dans le titre, mon CPU est a 100% en permanence et mon ordinateur est sérieusement ralenti.
j ai scanné avec avast pro, il n a rien trouvé et j ai aussi scanné avec spybot qui m a trouvé 4 ou 5 malwares mais le probleme persiste toujours.

je vous poste le rapport hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:00:35, on 26/11/2009
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\loukoom\AppData\Local\uccqqegm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - D:\Super Ad Blocker 4.6\SABBHO.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [uccqqegm] "c:\users\loukoom\appdata\local\uccqqegm.exe" uccqqegm
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SABWinLogon - D:\Super Ad Blocker 4.6\SABWINLO.DLL (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - D:\Super Ad Blocker 4.6\SABSVC.EXE (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 6542 bytes

merci d avance pour votre aide
Configuration: Windows 7
Firefox 3.5.5

24 réponses

  1. Stop!!! Je vais finir par rougir....
    0
    1. pour moi ca en est... :-)
      0
      1. De rien, j'ai l'air de faire des miracles...
        0
        1. ca marche impeccable!!! merci pour tout...
          0
          1. Sinon fait un coup de balais avec ccléaner et tune up utilities (1 mois d'essais gratuit).
            0
            1. ok bon je redémarre et je te tiens au courant.

              merci
              0
              1. c est fait mais c est toujours aussi lent. il faut que je redémarre l'ordinateur?
                0
                1. Peut -être le fichier hosts a vider...

                  La faute a spybot (qui ralentit internet a mort)

                  Va dans C:\windows\system32\drivers\etc\

                  Ouvre le fichier hosts vide le complètement. (control+A et supprimer) puis copie ceci:

                  # Copyright (c) 1993-2006 Microsoft Corp.
                  #
                  # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
                  #
                  # This file contains the mappings of IP addresses to host names. Each
                  # entry should be kept on an individual line. The IP address should
                  # be placed in the first column followed by the corresponding host name.
                  # The IP address and the host name should be separated by at least one
                  # space.
                  #
                  # Additionally, comments (such as these) may be inserted on individual
                  # lines or following the machine name denoted by a '#' symbol.
                  #
                  # For example:
                  #
                  #      102.54.94.97     rhino.acme.com          # source server
                  #       38.25.63.10     x.acme.com              # x client host
                  
                  
                  # This list is Copyright 2000-2008 Safer Networking Limited
                  
                  

                  0
                  1. par contre internet est toujours ralenti...
                    0
                    1. ca y est c est bon... le CPU est redescendu. merci beaucoup pour ton aide ainsi qu'à jong7
                      0
                      1. https://www.commentcamarche.net/contents/850-cmd-cmd-exe

                        pour la petite info.
                        0
                        1. heu? il faut les taper ou les lignes de commande?
                          0
                          1. Tu tue le processus ensuite tu supprime le processus a la main:

                            C:\Users\loukoom\AppData\Local\uccqqegm.exe

                            tu peux faire ca en ligne de commande:

                            Taskkill /im uccqqegm.exe 
                            erase C:\Users\loukoom\AppData\Local\uccqqegm.exe
                            exit 
                            0
                            1. pour le supprimer il faut que j utilise hijackthis?
                              0
                              1. C'est un trojan!!!

                                Supprime-le!!!

                                a-squared 4.5.0.43 2009.11.26 Trojan.Win32.Skintrim!IK
                                Ikarus T3.1.1.74.0 2009.11.26 Trojan.Win32.Skintrim

                                Et le fait que nod32 le trouve suspect confirme particulièrement le trojan:

                                NOD32 4639 2009.11.26 a variant of Win32/Skintrim.BZ

                                0
                                1. bonjour geolim4,
                                  voici le rapport pour uccqqegm.exe:

                                  Antivirus Version Dernière mise à jour Résultat
                                  a-squared 4.5.0.43 2009.11.26 Trojan.Win32.Skintrim!IK
                                  AhnLab-V3 5.0.0.2 2009.11.26 -
                                  AntiVir 7.9.1.78 2009.11.26 -
                                  Antiy-AVL 2.0.3.7 2009.11.26 -
                                  Authentium 5.2.0.5 2009.11.26 -
                                  Avast 4.8.1351.0 2009.11.26 -
                                  AVG 8.5.0.425 2009.11.26 -
                                  BitDefender 7.2 2009.11.26 -
                                  CAT-QuickHeal 10.00 2009.11.26 -
                                  ClamAV 0.94.1 2009.11.26 -
                                  Comodo 3045 2009.11.26 -
                                  DrWeb 5.0.0.12182 2009.11.26 -
                                  eSafe 7.0.17.0 2009.11.24 -
                                  eTrust-Vet 35.1.7143 2009.11.26 -
                                  F-Prot 4.5.1.85 2009.11.25 -
                                  F-Secure 9.0.15370.0 2009.11.24 -
                                  Fortinet 4.0.14.0 2009.11.26 -
                                  GData 19 2009.11.26 -
                                  Ikarus T3.1.1.74.0 2009.11.26 Trojan.Win32.Skintrim
                                  Jiangmin 11.0.800 2009.11.26 -
                                  K7AntiVirus 7.10.905 2009.11.25 -
                                  Kaspersky 7.0.0.125 2009.11.26 -
                                  McAfee 5813 2009.11.25 -
                                  McAfee+Artemis 5813 2009.11.25 -
                                  McAfee-GW-Edition 6.8.5 2009.11.26 -
                                  Microsoft 1.5302 2009.11.26 -
                                  NOD32 4639 2009.11.26 a variant of Win32/Skintrim.BZ
                                  Norman 6.03.02 2009.11.25 -
                                  nProtect 2009.1.8.0 2009.11.26 -
                                  Panda 10.0.2.2 2009.11.26 -
                                  PCTools 7.0.3.5 2009.11.26 -
                                  Prevx 3.0 2009.11.26 -
                                  Rising 22.23.03.10 2009.11.26 -
                                  Sophos 4.48.0 2009.11.26 -
                                  Sunbelt 3.2.1858.2 2009.11.26 -
                                  Symantec 1.4.4.12 2009.11.26 -
                                  TheHacker 6.5.0.2.079 2009.11.26 -
                                  TrendMicro 9.100.0.1001 2009.11.26 -
                                  VBA32 3.12.12.0 2009.11.26 -
                                  ViRobot 2009.11.26.2056 2009.11.26 -
                                  VirusBuster 5.0.21.0 2009.11.25 -
                                  Information additionnelle
                                  File size: 353280 bytes
                                  MD5...: 4c69a9ba83a8875595482880a4927211
                                  SHA1..: b96978e7eb19eb1fdc919142b962c43ff18d39bc
                                  SHA256: 7ab8d6bb9c3dee42185691cba4d176d9a4d07aedddb26285f4b80837b6b0232b
                                  ssdeep: 6144:ot7RO7tZBlHJrtKmHldQ6us5A25DccKfoZXtHWafo4WFg5FBmXkjrp2:g4v
                                  XfzP5AmMf0XtH625/mXk3
                                  PEiD..: -
                                  PEInfo: PE Structure information

                                  ( base data )
                                  entrypointaddress.: 0x2b40
                                  timedatestamp.....: 0x3f57aeec (Thu Sep 04 21:30:20 2003)
                                  machinetype.......: 0x14c (I386)

                                  ( 4 sections )
                                  name viradd virsiz rawdsiz ntrpy md5
                                  .text 0x1000 0x1d46 0x1e00 5.97 b96abc0309200f70bb283daccbdf3427
                                  .rdata 0x3000 0x27aa 0x2800 6.63 6cec878d0fbb106a56dd774e26abd097
                                  .data 0x6000 0x5146c 0x51600 7.18 15f4997a4c9114afa07dd962561652f0
                                  .rsrc 0x58000 0x328 0x400 2.53 c2de0e652408c702941d52d7ab10d7e9

                                  ( 5 imports )
                                  > GDI32.dll: CreateSolidBrush, SelectObject, CreateCompatibleDC, SetTextColor, DeleteDC, DeleteObject, SetBkMode, SetBkColor
                                  > OLEAUT32.dll: -, -, -, -
                                  > KERNEL32.dll: lstrlenA, GetSystemDefaultLangID, GetUserDefaultLangID, GetCurrentThread, ResetEvent, GetOEMCP, VirtualAlloc, FindResourceA, Sleep, VirtualFree, WriteFile, HeapCreate, IsValidCodePage, CreateProcessA, InterlockedExchange, GetModuleHandleW, GetACP, CloseHandle, ReadFile, GetModuleHandleA, TlsFree, MapViewOfFile, RaiseException, InterlockedCompareExchange, GetCommandLineA, HeapSize, WideCharToMultiByte, GetCommandLineW, LockResource, GetCurrentProcessId, GetEnvironmentStrings, lstrlenW, GlobalUnlock, GetEnvironmentStringsW, GetThreadLocale, LCMapStringA, GetConsoleCP, GlobalFree, LCMapStringW, GetLastError, InterlockedIncrement, ExitProcess, CreateFileA, TlsSetValue, GetFileType, CreateEventA, CreateFileW, GetTimeZoneInformation, GlobalLock, WaitForMultipleObjects, FindFirstFileW, DeleteFileW, CompareStringA, FindFirstFileA, CompareStringW, GetProcessHeap, GetProcAddress, GetFullPathNameA, GetWindowsDirectoryA, DeleteFileA, GetStartupInfoA, LoadLibraryA, GetVersionExA, VirtualProtect, TlsAlloc, GetTickCount, QueryPerformanceCounter, FreeLibrary, lstrcmpiA, SetHandleCount, GetSystemTime, EnterCriticalSection, WriteConsoleW, LeaveCriticalSection, GetCurrentThreadId, SetEndOfFile, VirtualQuery, GetVersion, TerminateProcess, SetEnvironmentVariableA, GetSystemDirectoryA, MulDiv, SetUnhandledExceptionFilter, CreateThread, SetFilePointer, CreateMutexA, MultiByteToWideChar, LoadLibraryExW, UnhandledExceptionFilter, GetModuleFileNameA, FlushFileBuffers, HeapAlloc, IsDebuggerPresent, GetModuleFileNameW, GetEnvironmentVariableA, SetLastError, FormatMessageA, InterlockedDecrement, FindClose, InitializeCriticalSection, FormatMessageW, SetEvent, SetFileAttributesA, GetStringTypeW, HeapReAlloc, GetSystemTimeAsFileTime, GetStringTypeA, LoadLibraryW, GetCPInfo, SetStdHandle, FreeEnvironmentStringsW, SetErrorMode, LocalAlloc, GetLocaleInfoA, GetConsoleMode, GetCurrentProcess, DeleteCriticalSection, FreeEnvironmentStringsA, HeapDestroy, WaitForSingleObject, GetFileAttributesA, GetConsoleOutputCP, GetStdHandle, GetSystemDefaultLCID
                                  > USER32.dll: BeginPaint, PeekMessageA, EndPaint, DispatchMessageA, CreateWindowExA, GetWindowLongA, GetWindow, IsWindowEnabled, TranslateMessage, GetSystemMetrics, DefWindowProcA, GetParent, GetMessageA, DestroyWindow, GetClientRect, SendMessageA, GetDC, SetWindowPos, PostQuitMessage, DestroyMenu, MoveWindow, SetForegroundWindow, GetWindowRect, SetWindowLongA, SetWindowTextA, CheckMenuItem, GetSubMenu, SetTimer, LoadCursorA, LoadIconA, TrackPopupMenu, GetFocus, SetDlgItemTextA, GetSysColor, SystemParametersInfoA, IsWindowVisible, InvalidateRect, CallWindowProcA, ShowWindow
                                  > MSVCRT.dll: _strcmpi, _XcptFilter, exit, _acmdln, __getmainargs, _onexit, __dllonexit, _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, _exit

                                  ( 0 exports )
                                  RDS...: NSRL Reference Data Set
                                  -
                                  pdfid.: -
                                  trid..: Win32 Executable MS Visual C++ (generic) (65.2%)
                                  Win32 Executable Generic (14.7%)
                                  Win32 Dynamic Link Library (generic) (13.1%)
                                  Generic Win/DOS Executable (3.4%)
                                  DOS Executable Generic (3.4%)
                                  sigcheck:
                                  publisher....: n/a
                                  copyright....: n/a
                                  product......: n/a
                                  description..: n/a
                                  original name: n/a
                                  internal name: n/a
                                  file version.: n/a
                                  comments.....: n/a
                                  signers......: -
                                  signing date.: -
                                  verified.....: Unsigned
                                  0
                                  • 1
                                  • 2