Scan antivirus impossible
Résolubonjour, j'aimerai savoir pourquoi il m'est impossible de faire un scan ,avec Eset online scanner ou House call ou avec d'autres logiciels?lorsque je veux les télécharger, il ne se passe rien du tout. j'ai peut etre un virus dans mon pc?
mon antivirus est Avira antivir et lui ne trouve rien
merci pour votre aide
47 réponses
Problème rencontré : sous Windows Vista avec Firefox 3.6.2, il est impossible de télécharger ou d'exécuter des scans en ligne comme Eset Online Scanner ou HouseCall, et l'antivirus Avira ne détecte rien. Plusieurs pistes s'ouvrent : démarrer en mode sans échec, désactiver l'UAC sous Vista, puis utiliser des outils de désinfection comme OTM pour nettoyer les entrées de registre et les services suspects. D'autres recommandations évoquent ZHPDiag, HijackThis et CCleaner comme outils de diagnostic et de nettoyage, tandis que des nettoyeurs temporaires et de registre peuvent être proposés séparément. En dernier recours, la génération et l'analyse des rapports des outils permettent d'identifier des infections profondes ou des services problématiques, accompagnées d'une réinitialisation du système et d'une mise à jour des correctifs critiques.
-
bonjour,
merci à toi pour tout le temps que tu m'as consacré!!!!!!
J'ai installé tous les programmes cités auparavant.
malgré tout ca le pc rame un peu plus, firefox ne s'ouvre plus et yahoo messenger a disparu...
a bientot peut-etre
Cordialement,mlsdlouk -
Contributeur sécuritéRe,
On finalise, dans l'ordre :
▶ Lance Hijackthis ( ou ce fichier : )
▶ Choisis " Do a system scan only "
▶ Coche ces lignes sur leurs gauche : (et uniquement celles ci !!)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
▶ Clique sur " FIX CHECKED " et valide au message d'avertissement.
▶ Redémarre ton PC .
Tutoriel , Fixer les lignes avec Hijackthis
====================================
► Nettoyage :
Passe une fois tout les deux jours un coup de nettoyage avec ATF-Cleaner, puis CCleaner.
Passe une fois tous les 15 jours une défragmentation.
► Logiciels de protection :
⇒ Antivirus:
Garde antivir.
⇒ Anti-spyware:
Désactive Windows defander :
https://www.microsoft.com/en-us/windows/
Télécharge et Installe Spyware-blaster,qui est léger en ressources, met le a jour régulièrement,et active toutes les protections (« Enable all protection »).
Télécharge et installe Spyware Guard et garde le sur ton PC.
Garde Malwarebytes en complément.
⇒ Firewall:
Désactive le firewall de windows , car il ne vaut rien :
Sous XP
Sous Vista
Je te conseille si tu n'as pas , afin d'installer un pare-feu pour mieux sécuriser ton PC , voici quelque uns que je trouve très bien :
Online Armor Personal Firewall (gratuit)
Kerio
PC Tools Firewall Plus (<= N'INSTALLE PAS SPYWARE DOCTOR !!!!)
Tutoriel Online Armor
Tutoriel Kerio
Tutoriel PC Tools
⇒ Navigateur:
Pour + de sécurité; lance Firefox et installe les trois extensions de sécurité suivantes :
WOT : pour se protéger des sites malveillants.
Tuto
No Script
Tutoriel et test No Script
Adblock Plus , Pour bloquer les pubs.
Tutoriel d'utilisation
► Surveillance :
Fais un scan avec ton antivirus a chaque fin de semaine (mets le à jour avant de lancer le scan)
Mets a jour régulièrement Malwarebytes', fais un scan rapide a chaque semaine.
Mets a jour régulièrement Windows, vérifie que les mises a jours automatiques sont bien activés :
Démarrer > Panneau de configuration
choisis l'icône Windows Update, coche la case Mise à jour automatique. Ainsi, Windows et les autres produits de Microsoft comme Internet Explorer, Windows Defender, Windows Media Player etc...
Mets a jour régulièrement Java, adobe reader, comme expliqué
Utilise régulièrement Update checker comme expliqué.
Fais régulièrement une sauvegarde de donnés sur un support externe; ça peut être utile au cas où le système plante.
► Prévention:
Je t'invite à lire ces articles pour éviter une ré-infection au futur: [30 Minutes de lecture très instructive]
Sécuriser son ordinateur et connaitre les menaces (Merci Malekal)
Prévention & Protection sur internet (Grand merci aux auteurs de ce très bon PDF)
Voila, bonne lecture et une fois tous ceci fait et lu tu peux mettre le topic comme résolu.
Bon surf et soit plus vigilent(e) a l'avenir ! ;)
Cordialement Fix.
++ -
bonjour,
désolé, j'ai completement zappé en rentrant du boulot.........
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:04:28, on 03/04/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal
Running processes:
C:\Program Files\Philips\CamSuite\1.0.9.0\ACPGUI.dll
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Windows\vspc1030.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\IELowutil.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [spc1030] C:\Windows\vspc1030.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Philips Intelligent Agent] "C:\Program Files\Philips\Intelligent Agent\Philips Intelligent Agent.exe" /SILENT
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [EPSON Stylus SX200 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE /FU "C:\Windows\TEMP\E_SE1CB.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{018D29E4-DB84-49C5-AE26-A7572602C740}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{018D29E4-DB84-49C5-AE26-A7572602C740}: NameServer = 192.168.1.1
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: ACPService - Unknown owner - C:\Program Files\Philips\CamSuite\1.0.9.0\ACPService.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -
Contributeur sécuritéSlt où est le rapport Hijackthis ? ;)
-
j'ai redémarrer le pc lorsque celui ci me l'a demandé...
me trouvant encore au taf, secteur médical, le scan Hijackthis sera fait demain matin, 08h30, de retour à mon domicile.
ta question : "Euh ... tu es bien administrateur du PC ?", "ca parait quand meme bizarre...." me turlupine depuis quelques jours quand meme................
Bonne soirée et encore merci pour lout le temps que tu consacres sur mon problème.
mlsdlouk -
Contributeur sécuritéRe,
Le logiciel t'a demandé de redémarrer le PC, tu l'a fait ?
Si non je vais pas m'embêter à cause des ces m**des d'AV ...
Refais un scan Hijackthis et colle le rapport -
http://www.cijoint.fr/cjlink.php?file=cj201004/cijHgOjkV3.txt
-
All processes killed
========== REGISTRY ==========
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWFSBLK\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMONFLT\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWRDR\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWSP\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWTDI\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IDSVIX86\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMDNS\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMEVENT\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMFW\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMIDS\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMNDISV\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMREDRV\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMTDI\ scheduled to be deleted on reboot.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LeSeB
->Temp folder emptied: 2592030 bytes
->Temporary Internet Files folder emptied: 12532582 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 57999282 bytes
->Flash cache emptied: 933 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1548 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 1469169488 bytes
Total Files Cleaned = 1 471,00 mb
OTM by OldTimer - Version 3.1.10.1 log created on 04022010_175303
Files moved on Reboot...
C:\Users\LeSeB\AppData\Local\Temp\~DF891A.tmp moved successfully.
File C:\Users\LeSeB\AppData\Local\Temp\~DFC289.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFC294.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFC47F.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFC48A.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFC552.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFC55E.tmp not found!
C:\Users\LeSeB\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1YBPWF2P\affich-17168187-scan-antivirus-impossible[1].txt moved successfully.
C:\Users\LeSeB\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Windows\temp\ACPTrace\Fri Apr 02 17.50.15 2010 33368.log moved successfully.
C:\Windows\temp\JETBB23.tmp moved successfully.
Registry entries deleted on Reboot...
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWFSBLK\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMONFLT\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWRDR\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWSP\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWTDI\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IDSVIX86\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMDNS\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMEVENT\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMFW\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMIDS\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMNDISV\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMREDRV\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMTDI\ scheduled to be deleted on reboot. -
apres avoir stopper l'UAC et redemarrer le pc, celui est resté bloquer sur "Microsoft Corporation". Je l'ai eteint et celui ci maintenant sur la page "réparation des problèmes survenu lors du redemarrage".
j'attends...... -
Contributeur sécuritéRe,
Petite faute de ma pars (merci Jack')
Refais un script OTM avec ça:
:reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWFSBLK]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMONFLT]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWRDR]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWSP]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWTDI]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IDSVIX86]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMDNS]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMEVENT]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMFW]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMIDS]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMNDISV]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMREDRV]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMTDI]
:commands
[emptytemp]
[reboot]
Colle le rapport obtenu + un nouveau ZHPDiag (<-- via cijoint.fr) -
Contributeur sécuritéBonjour,
je pars me renseigner pour toi sur un truc et je reviens.
@+ -
http://www.cijoint.fr/cjlink.php?file=cj201004/cijqmpzegt.txt
-
bonjour,
All processes killed
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LeSeB
->Temp folder emptied: 71240144 bytes
->Temporary Internet Files folder emptied: 112082949 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 80572182 bytes
->Flash cache emptied: 1257 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12282 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 733188929 bytes
Total Files Cleaned = 951,00 mb
OTM by OldTimer - Version 3.1.10.1 log created on 04012010_170850
Files moved on Reboot...
C:\Users\LeSeB\AppData\Local\Temp\~DFA730.tmp moved successfully.
File C:\Users\LeSeB\AppData\Local\Temp\~DFA9EC.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFA9F7.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFCC48.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFE5C3.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFE5CE.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFE690.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DFE744.tmp not found!
C:\Users\LeSeB\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G27AQ56Q\affich-17168187-scan-antivirus-impossible[1].txt moved successfully.
C:\Users\LeSeB\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Windows\temp\ACPTrace\Thu Apr 01 17.06.21 2010 38251.log moved successfully.
C:\Windows\temp\JETCFCC.tmp moved successfully.
Registry entries deleted on Reboot... -
Contributeur sécuritéje l'ai meme fais 2 fois avant de l'envoyer.....
Ok ... je vois mieux maintenant :)
Peux-tu me poster le PREMIER rapport ? Il se trouve dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
+ le ZHPDiag ;)
@+ & bonne soirée. -
bonsoir,
j'ai bien tout copié-collé comme indiqué!!!je l'ai meme fais 2 fois avant de l'envoyer.....
je suis au taf jusqu'à 8h donc je poste le rapport demain à partir de 14h30.
Bonne soirée et merci beaucoup pour ton aide -
Contributeur sécuritéRe,
Euh ... tu as bien tout copié-collé ?
Refais un scan ZHPDiag et colle le rapport obtenu stp (via cijoint). -
quand je veux enregistrer le fichier il me note qu'il est impossible de prendre log.alors je l'ai copié:
All processes killed
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LeSeB
->Temp folder emptied: 194308 bytes
->Temporary Internet Files folder emptied: 2357877 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 2,00 mb
OTM by OldTimer - Version 3.1.10.1 log created on 04012010_171547
Files moved on Reboot...
C:\Users\LeSeB\AppData\Local\Temp\~DF2E70.tmp moved successfully.
File C:\Users\LeSeB\AppData\Local\Temp\~DF749E.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DF9090.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DF909B.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DF934D.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DF9366.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DF93F7.tmp not found!
File C:\Users\LeSeB\AppData\Local\Temp\~DF9404.tmp not found!
C:\Users\LeSeB\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZF78071H\affich-17168187-scan-antivirus-impossible[1].txt moved successfully.
C:\Users\LeSeB\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Windows\temp\ACPTrace\Thu Apr 01 17.11.14 2010 37658.log moved successfully.
C:\Windows\temp\JETB78B.tmp moved successfully.
Registry entries deleted on Reboot... -
Contributeur sécuritéRe,
Avant de faire ZHPDiag fais ceci :
Si vous êtes sous Vista Désactivez l'UAC
Télécharge OTM (Old Timer) sur ton bureau:
▶ Sous XP: Double-clique sur OTM.exe afin de le lancer.
* Sous Vista: fais un clic droit sur OTM et choisis "exécuter en tant qu'administrateur"
▶ Copie (Ctrl+C) le texte suivant ci-dessous :
:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWFSBLK]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMONFLT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWRDR]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWSP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWTDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IDSVIX86]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMDNS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMEVENT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMFW]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMIDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMNDISV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMREDRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMTDI]
:commands
[emptytemp]
[reboot]
▶ Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
▶ Clique maintenant sur le bouton MoveIt! puis ferme OTM.
Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. => Accepte en cliquant sur YES.
▶ Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
* Note: Le nom du rapport correspond au moment de sa création : date_heure.log -
http://www.cijoint.fr/cjlink.php?file=cj201004/cijqTtCnDX.txt
-
http://www.cijoint.fr/cjlink.php?file=cj201004/cij2DagB20.txt
j'ai refait une deuxieme fois
- 1
- 2
- 3