Mon pc bug / rame ...

Bonjours a tous ,

Voila depuis maintenant plus de 2 semaines mon pc plante et rame ...

Déjà , quand je suis sur le bureau sans rien faire mon UC et utilisée a 50% hors avant sans rien faire j'étais a 0 ...

Et quand par exemple des fois je suis sur photoshop rien que de faire >> Fichier >> Nouveau le programme ne réponds plus pareil avec firefox etc .... et parfois il rame sévère !

Donc hier vue que sa dure depuis quelque temps j'ai déjà fait >> Néttoyage du disque , Défragmentation du disque dur , Ccleaner , MalwareBytes , Antivir , remis a jour quelque logiciel etc ....

Mais rien n'y fait il plante toujours et rame ...

Ma config si besoin :

4000+X2
HD 4850 Golden Sample
3Go ddr2
disque dur de 200go ( seulement 54Go utilisée ... )
Windows 7

Voila si quelqu'un aurais une solution a mon problème car la sa deviens atroce !

Merci d'avance ;)

38 réponses

Résumé de la discussion

Problème récurrent observé sur un PC fonctionnant sous Windows 7, où l'ordinateur se met à ramer fortement et à planter même lorsqu'aucune action lourde n'est en cours, affectant Photoshop et Firefox. Puisieurs tentatives ont été effectuées, notamment Nettoyage de disque, défragmentation et outils de sécurité, mais les ralentissements persistent et des plantages surviennent lorsque le système sollicite des applications comme le traitement d'image. L'historique des diagnostics mentionne des éléments suspects dans les rapports, avec des scans MalwareBytes et ComboFix qui ont été lancés, puis l'observation d'une possible infection et d'antivirus concurrents en activité. En cas de suite, les données affichent une activité suspecte et des infections potentielles nécessitant une procédure complète de nettoyage et de réinstallation ciblée du système.

Bobot (l’IA à votre service)
  1. 1. Fais la mise à jour de MalwareByte's Anti-Malware
    2. Démarre en mode sans échec (en tapotant F8 au démarrage), lance MalwareByte's Anti-Malware et fais un scan complet !

    A la fin, supprime tout ce qui trouve et sauvegarde le rapport sur le Bureau !

    Redémarre en normal et montre le rapport
    1. Re ,

      Toujours au même points ....

      Mais bon cette semaines je suis pas chez moi mais je l'ai utilisée vendredi soir c'était pareil ...
      1. Re , désole du temps de réponse j'étais pas chez moi ce week end ....

        Effectivement c'est bon , voici le rapport :

        Le volume dans le lecteur C n'a pas de nom.
        Le num'ro de s'rie du volume est D2EE-DA5C

        R'pertoire de C:\Program Files

        08/06/2010 19:23 <REP> .
        08/06/2010 19:23 <REP> ..
        12/10/2009 12:42 <REP> Activision
        28/03/2010 12:42 <REP> Adobe
        27/10/2009 16:10 <REP> Alcohol Soft
        31/10/2009 16:09 <REP> AMD
        11/04/2010 19:19 <REP> Apowersoft
        05/06/2010 10:02 <REP> ATI
        22/12/2009 17:15 <REP> ATI Technologies
        27/12/2009 13:39 <REP> Audacity
        05/06/2010 10:24 <REP> Avira
        08/05/2010 13:29 <REP> AVS4YOU
        08/05/2010 16:12 <REP> Boilsoft ASF Converter
        16/03/2010 16:09 <REP> Call of Duty Modern Warfare 2
        05/06/2010 09:44 <REP> CCleaner
        02/11/2009 21:00 <REP> Codemasters
        05/06/2010 13:33 <REP> Common Files
        17/12/2009 14:06 <REP> DIFX
        14/12/2009 10:19 <REP> DivX Pro VFW
        22/12/2009 16:13 <REP> Driver Sweeper
        01/08/2009 10:27 <REP> DVD Maker
        31/10/2009 17:29 <REP> EA Games
        31/10/2009 14:59 <REP> Electronic Arts
        28/10/2009 11:26 <REP> eMule
        12/10/2009 12:40 <REP> FileHippo.com
        11/04/2010 14:03 <REP> Flash 32
        02/11/2009 11:43 <REP> Futuremark
        05/06/2010 13:35 <REP> Internet Explorer
        10/11/2009 13:18 <REP> Java
        10/11/2009 11:56 <REP> JDownloader
        09/05/2010 15:52 <REP> K-Lite Codec Pack
        27/10/2009 10:30 <REP> KONAMI
        02/11/2009 11:42 <REP> Lavalys
        09/05/2010 15:52 <REP> Malwarebytes' Anti-Malware
        16/01/2010 15:29 <REP> MediaCoder
        12/10/2009 18:25 <REP> Microsoft
        14/07/2009 09:50 <REP> Microsoft Games
        09/11/2009 20:51 <REP> Microsoft Games for Windows - LIVE
        05/06/2010 09:54 <REP> Microsoft Silverlight
        15/03/2010 00:17 <REP> Movie Maker 2.6
        11/04/2010 12:05 <REP> Mozilla Firefox
        11/11/2009 12:18 <REP> Mozilla Firefox 3.6 Beta 1
        23/11/2009 12:48 <REP> Mozilla Firefox 3.6 Beta 3
        27/12/2009 13:33 <REP> MP3Gain
        14/07/2009 06:52 <REP> MSBuild
        08/06/2010 19:20 <REP> MSECACHE
        14/12/2009 10:19 <REP> MultiProxy
        02/11/2009 21:19 <REP> OpenAL
        17/12/2009 14:06 <REP> PC Connectivity Solution
        14/07/2009 06:52 <REP> Reference Assemblies
        09/11/2009 20:48 <REP> Rockstar Games
        12/10/2009 12:42 <REP> Saints Row 2
        28/11/2009 18:25 <REP> ScreenshotCaptor
        12/12/2009 15:59 <REP> SFR
        19/05/2010 21:38 <REP> Sony
        09/05/2010 13:21 <REP> Sony Ericsson
        09/05/2010 14:53 <REP> Spybot - Search & Destroy
        03/11/2009 10:22 <REP> SystemRequirementsLab
        09/05/2010 15:52 <REP> Total Video Converter
        13/05/2010 18:16 <REP> TubeMaster++
        06/06/2010 18:47 <REP> TuneUp Utilities 2010
        01/11/2009 13:29 <REP> Ubisoft
        05/05/2010 21:32 <REP> Veetle
        12/10/2009 12:44 <REP> VideoLAN
        14/12/2009 10:19 <REP> VirtualDub
        20/12/2009 17:00 <REP> Visicom Media
        01/08/2009 10:27 <REP> Windows Defender
        01/08/2009 10:27 <REP> Windows Journal
        12/10/2009 18:25 <REP> Windows Live
        12/10/2009 18:24 <REP> Windows Live SkyDrive
        12/05/2010 23:41 <REP> Windows Mail
        16/10/2009 17:50 <REP> Windows Media Player
        11/10/2009 21:37 <REP> Windows NT
        01/08/2009 10:27 <REP> Windows Photo Viewer
        14/07/2009 06:52 <REP> Windows Portable Devices
        01/08/2009 10:27 <REP> Windows Sidebar
        16/01/2010 15:34 <REP> WinFF
        13/04/2010 22:09 <REP> WinPcap
        05/06/2010 09:54 <REP> WinRAR
        06/06/2010 15:48 <REP> ZHPDiag
        05/06/2010 11:25 <REP> ZHPFix
        0 fichier(s) 0 octets
        81 R'p(s) 56ÿ986ÿ996ÿ736 octets libres
        Le volume dans le lecteur C n'a pas de nom.
        Le num'ro de s'rie du volume est D2EE-DA5C

        R'pertoire de C:\Program Files\fichiers communs

        Le volume dans le lecteur C n'a pas de nom.
        Le num'ro de s'rie du volume est D2EE-DA5C

        R'pertoire de C:\Program Files\common files

        05/06/2010 13:33 <REP> .
        05/06/2010 13:33 <REP> ..
        17/01/2010 14:10 <REP> Adobe
        22/12/2009 16:24 <REP> ATI Technologies
        08/05/2010 13:29 <REP> AVSMedia
        02/11/2009 11:45 <REP> Futuremark Shared
        31/10/2009 18:02 <REP> InstallShield
        05/06/2010 09:45 <REP> Java
        05/11/2009 11:40 <REP> Macrovision Shared
        05/06/2010 09:47 <REP> microsoft shared
        11/12/2009 23:41 <REP> NSV
        11/12/2009 23:40 <REP> Nullsoft
        14/07/2009 04:37 <REP> Services
        14/07/2009 04:37 <REP> SpeechEngines
        01/08/2009 10:27 <REP> System
        20/12/2009 19:22 <REP> Vbox
        12/10/2009 18:17 <REP> Windows Live
        0 fichier(s) 0 octets
        17 R'p(s) 56ÿ986ÿ996ÿ736 octets libres
        Le volume dans le lecteur C n'a pas de nom.
        Le num'ro de s'rie du volume est D2EE-DA5C

        R'pertoire de C:\

        ====== Supression des fichiers temporaires ======
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\alm.log
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\amt.log
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\AUCHECK_CORE.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\AUCHECK_PARSER.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\catchme.dll
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\clockgen.ini
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\csxs-PHXS.log
        C:\Users\Cedric\AppData\Local\Temp\FXSAPIDebugLogFile.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\jusched.log
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\swtag.log
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\TUM72A2.tmp
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\TUUUninstallHelper.exe
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\TWAIN.LOG
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\Twain001.Mtx
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\Twunk001.MTX
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\Twunk002.MTX
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\wmsetup.log
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\+HszbK4rc3m74cq3XIEZ9Bpfcy8=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\2Fb12FoTdlDwhGACxOVT2FcjssJMtk=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\2Fm41VoLjXkFOMURdzIa2Facr7kQQ=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\2FSTexpHjOLVohJsr2FQHo0LRKeRA=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\2Fzk1a8Add9GZwJMcNqsc0yCI2F6A=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\32Jj1MhIaDnQre4HnXwpRFYWQvA=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\3LUXGby2F+U42F5SSiKvOUWuUGbDw=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\4eNakBniLtZJEnaVRpD2FQzdpeQE=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\67n2eCZagxjrgFQ744Zt+J2s41E=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\6x8eZSXWA+sY5p8pBy2qKVTEcqQ=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\7wdLC7bBYBsdVbAUVJ1Y2FfeDmQ0=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\9spuCorK87WdwM+ZDyBWuM1s+SY=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\AQIIvjtMXwtJODshv0nsQmo8axc=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\d36UPrvkXPOdIhZrf7C925Nr6Yo=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\DJLHTv3gdydRia46ibnqtgX4PFY=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\Ew5RwyuTBuI2iZNeNE1pWL262O4=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\GAMzxNT7KNJuLh+x0xSUZ9N8h2c=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\H9ctZpenqeiAEP9W7+6GY1773kE=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\hbcRmLrlHW32LWTPZcDmV8H2lcs=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\hyr26kAEM2Fyn2FwQanQCuafRc7WY=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\iCMzSwFOkzLWIHa5bw6SaB70ekc=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\kOzNiA9XLoyhEccQAbwhlMY+xZs=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\kWge9yHbbuRcQLQCVMzv3zwr2FfE=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\LkV1zs0+A2FPuic94z9bjYqDCoEw=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\m3yG7ZJdrZ1Vsk66gwXZ9Qm0M38=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\MKV2F212VSLkKP+qhhWucAnfLMW4=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\mMsY4FuGrCwO2FisdU369+zQeygo=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\oPcWvDrdPL9WVPqBkoUDZV5C5Jg=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\PjuBxm+xMOkwk0nPUGw1hW+tW0I=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\PZAJRUMUUHyegK7uUvdtfCFWUEs=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\qWZl21m07KCzlMFxWiUjNvZWcCo=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\Sk5SfZGzcRK3jucfSXAPKt9NpF0=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\SWZNPH4JYReuLcNg2FumDX4lM1rE=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\MessengerCache\trgrkdQs7AEKsoBUOFniAzbc7uw=
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp\plugin-crossdomain-1.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp\plugin-crossdomain-2.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp\plugin-crossdomain.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp\plugin-test_domain.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp\plugin-yt_blacklist_domains.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-1\plugin-1
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-1\plugin-crossdomain-1.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-1\plugin-crossdomain.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-1\plugin-test_domain.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-1\plugin-yt_blacklist_domains.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-4\plugin-crossdomain-1.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-4\plugin-crossdomain-2.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-4\plugin-crossdomain.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\plugtmp-5\plugin-crossdomain.xml
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\tmpA68E.tmp\ipconfig.all.txt
        Fichier supprim' - C:\Users\Cedric\AppData\Local\Temp\UpdateWizard_102347\TUProduct.db
        C:\Users\Cedric\AppData\Local\Temp\FXSAPIDebugLogFile.txt

        ====== Scan MBR (Master Boot Record) ======

        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        kernel: MBR read successfully
        user & kernel MBR OK

        ====== Scan MBR (Master Boot Record) Après Fix ======

        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        kernel: MBR read successfully
        user & kernel MBR OK

        ====== Scan Terminé, merci d'avoir utiliser Recherche-Fix By Loicdem ======
        1. Impossible ...

          Dès que je fait entrer la page se quitte directement ....

          ET je suis sous Windows 7 pas Vista je sais pas si sa a un rapport ...
          1. Effectivement, Fais ça stp :

            Télécharge Recherche-Fix Vista.zip sur ton bureau
            Dézippe-le (en faisant clique-droit, extraire ici sur l'archive)
            Ça va donné un fichier avec mbr et Recherche-Fix.bat dedans
            Lance Recherche-Fix option 1, patiente, un rapport s'ouvrira
            Poste le sur le forum.
            1. Re !

              Bon sinon ce matin j'ai remarquer que dans les processus j'avais au mois 10 : Svchost.exe

              peut être une autre piste ?
              1. Ok ok pas de problème prends ton temps ;)

                Non pas de changements il peut allez bien ( la pour le moment il rame pas mais l'UC est quand même a 50% sans rien faire ) puis d'un seul coup il va se mettre a ramer et a bloquer , surtout quand j'utilise des logiciel en faite ....

                Sur le net sa peut allez ...
                1. Bon, ok, attend j'analyse le rapport et je te dis la suite !
                  1. j'ai obtenu sa :

                    GMER 1.0.15.15281 - http://www.gmer.net
                    Rootkit scan 2010-06-06 16:56:24
                    Windows 6.1.7600
                    Running: psfxwgfw.exe; Driver: C:\Users\Cedric\AppData\Local\Temp\pwryrpob.sys

                    ---- System - GMER 1.0.15 ----

                    INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E48AF8
                    INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E48104
                    INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E483F4
                    INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E30634
                    INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E30898
                    INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E481DC
                    INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E48958
                    INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E486F8
                    INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E48F2C
                    INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E491A8

                    ---- Kernel code sections - GMER 1.0.15 ----

                    .text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A61599 1 Byte [06]
                    .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A85F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
                    ? System32\drivers\wrmtmt.sys Le chemin d'accès spécifié est introuvable. !
                    ? System32\Drivers\spha.sys Le chemin d'accès spécifié est introuvable. !
                    .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x90A29000, 0x2FBFB8, 0xE8000020]
                    .text USBPORT.SYS!DllUnload 8F37DCA0 5 Bytes JMP 864FD1D8
                    .text peauth.sys 9255DC9D 28 Bytes [0F, 4F, D8, B9, 32, 66, 22, ...]
                    .text peauth.sys 9255DCC1 28 Bytes [0F, 4F, D8, B9, 32, 66, 22, ...]
                    PAGE peauth.sys 92563E20 101 Bytes [E4, 57, B0, 96, 21, A5, 63, ...]
                    PAGE peauth.sys 9256402C 102 Bytes CALL AF633902
                    ? C:\Users\Cedric\AppData\Local\Temp\catchme.sys Le fichier spécifié est introuvable. !

                    ---- User code sections - GMER 1.0.15 ----

                    .text C:\Program Files\Mozilla Firefox\firefox.exe[2504] ntdll.dll!LdrLoadDll 7748F585 5 Bytes JMP 012D13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

                    ---- Kernel IAT/EAT - GMER 1.0.15 ----

                    IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8B007042] \SystemRoot\System32\Drivers\spha.sys
                    IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8B0076D6] \SystemRoot\System32\Drivers\spha.sys
                    IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8B007800] \SystemRoot\System32\Drivers\spha.sys
                    IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8B00713E] \SystemRoot\System32\Drivers\spha.sys

                    ---- User IAT/EAT - GMER 1.0.15 ----

                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74272494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74255624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [742556E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [7427250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74268573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74264D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [742650CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [742651A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [742666D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [742682CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74268819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7426907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7426E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                    IAT C:\Windows\Explorer.EXE[1872] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74264C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

                    ---- Devices - GMER 1.0.15 ----

                    Device \FileSystem\Ntfs \Ntfs 853821F8
                    Device \FileSystem\fastfat \FatCdrom 8547C1F8
                    Device \Driver\NetBT \Device\NetBT_Tcpip_{2873AAC0-6F23-4051-8306-9D118A8B6DC4} 864AE1F8
                    Device \Driver\volmgr \Device\VolMgrControl 8537E1F8
                    Device \Driver\usbohci \Device\USBPDO-0 8650B1F8
                    Device \Driver\ACPI_HAL \Device\00000052 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
                    Device \Driver\usbohci \Device\USBPDO-1 8650B1F8
                    Device \Driver\usbohci \Device\USBPDO-2 8650B1F8
                    Device \Driver\usbohci \Device\USBPDO-3 8650B1F8
                    Device \Driver\usbohci \Device\USBPDO-4 8650B1F8
                    Device \Driver\usbehci \Device\USBPDO-5 8650C1F8
                    Device \Driver\volmgr \Device\HarddiskVolume1 8537E1F8

                    AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
                    AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

                    Device \Driver\volmgr \Device\HarddiskVolume2 8537E1F8

                    AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
                    AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

                    Device \Driver\cdrom \Device\CdRom0 863BD1F8
                    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 853801F8
                    Device \Driver\atapi \Device\Ide\IdePort0 853801F8
                    Device \Driver\atapi \Device\Ide\IdePort1 853801F8
                    Device \Driver\atapi \Device\Ide\IdePort2 853801F8
                    Device \Driver\atapi \Device\Ide\IdePort3 853801F8
                    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 853801F8
                    Device \Driver\NetBT \Device\NetBt_Wins_Export 864AE1F8
                    Device \Driver\iScsiPrt \Device\RaidPort0 865661F8
                    Device \Driver\usbohci \Device\USBFDO-0 8650B1F8
                    Device \Driver\usbohci \Device\USBFDO-1 8650B1F8
                    Device \Driver\usbohci \Device\USBFDO-2 8650B1F8
                    Device \Driver\usbohci \Device\USBFDO-3 8650B1F8
                    Device \Driver\usbohci \Device\USBFDO-4 8650B1F8
                    Device \Driver\usbehci \Device\USBFDO-5 8650C1F8
                    Device \FileSystem\fastfat \Fat 8547C1F8

                    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)

                    ---- Registry - GMER 1.0.15 ----

                    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
                    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
                    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
                    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
                    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
                    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x33 0xD0 0x09 0x80 ...
                    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
                    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
                    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x33 0xD0 0x09 0x80 ...

                    ---- EOF - GMER 1.0.15 ----
                    1. On va voir un truc !

                      Télécharge GMER à partir de ce lien : http://www.gmer.net#files - clic sur "Download EXE" et télécharge le fichier sur ton bureau.
                      Voir le tutorial GMER, ça peut peut-être t'aider : https://www.malekal.com/tutorial-gmer/

                      Désactive tes logiciels de protection (antivirus, antispyware etc) et ferme tous les programmes ouverts.
                      Double-clic sur le fichier GMER téléchargé.
                      IMPORTANT: Si une alerte de ton antivirus apparaît pour le fichier gmer.sys ou gmer.exe, laisse le s'executer.
                      Clic sur l'onglet "rootkit"
                      Laisse tout coché.
                      Clic sur Scan
                      Lorsque le scan est terminé, clic sur "Copy"

                      Ouvre le bloc-note et clic sur le Menu Edition / Coller
                      Le rapport doit alors apparaître.
                      Enregistre le fichier sur ton bureau et copie/colle le contenu ici.
                      1. Oué bizarre m'enfin il ma bien détectée sa quand même .... étrange ....

                        Bon sinon voila le rapport :

                        ===== Rapport WareOut Removal Tool =====

                        version 3.6.2

                        analyse effectuée le 06/06/2010 à 16:16:32,47

                        Résultats de l'analyse :
                        ========================

                        ~~~~ Recherche d'infections dans C:\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Program Files\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Users\Cedric\AppData\Roaming\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Users\Cedric\Bureau\ ~~~~

                        ~~~~ Recherche de détournement de DNS ~~~~

                        ~~~~ Recherche de Rootkits ~~~~

                        _______________________________________________________________________

                        catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2010-06-06 16:16:45
                        Windows 6.1.7600 NTFS

                        detected NTDLL code modification:
                        ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error

                        _______________________________________________________________________

                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
                        System REG_SZ

                        ~~~~ Recherche d'infections dans C:\Users\Cedric\AppData\Local\Temp\ ~~~~

                        ~~~~ Recherche d'infections dans C:\Users\Cedric\Start Menu\Programs\ ~~~~

                        ~~~~ Nettoyage du registre ~~~~

                        ~~~~ Tentative de réparation des entrées suivantes: ~~~~

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"

                        [HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
                        [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]

                        ~~~~ Vérification: ~~~~

                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
                        System REG_SZ

                        _________________________________

                        développé par http://pc-system.fr
                        _________________________________
                        1. Antivir.ink..... C'est un raccourci, je ne vois pas ou est le virus...

                          Enfin,

                          Enregistre wort sur ton bureau:

                          http://pc-system.fr/

                          Double-clique sur le fichier WORT.exe et sélectionne le Bureau à l'aide du bouton "Parcourir". Suis les instructions et double-clique sur le fichier Wareout Removal Tool.bat qui vient d'être créé sur le Bureau. Sélectionne l'option 1 et valide par entrée.

                          Poste le rapport qui s'affiche ensuite !
                          1. Bon alors hier sa bloquais sur le fichier:

                            HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer

                            La , l'analyse sais bien faite entièrement , est sa ma détectée 1 éléments infectée se trouvant dans : C:/Users\Public\Desktop\Antivir.ink

                            Que j'ai donc mis en quarantaines puis supprimer

                            ;)
                            • 1
                            • 2

                            Discussions similaires

                            Iptv beug

                            1 réponse