Mon PC rame énormément

Fermé
Bonjour,
URGENT
j'espère ke quelqu'un va pouvoir m'aider....
mon pc portable (windows XP, assez récent) rame ennnnnormément depuis quelques jours: il met 3 heures a ouvrir un fichier, ne lit la musique que de façon saccadée. pire depuis aujourd'hui, la "sourie" en dessous du clavier ne marche plus je dois faire avec une souris en usb.
j'ai téléchargé spyware terminator. j'ai lançé un scan: 3 objets critiques:

hotbar toolbar: HKCR\CLSID\74CC49F7-EB32-4AO......

HKLM\SOFTWARE\Microsoft....

HKCU\SOFTWARE\Microsoft\....

je prends la décision je l'espère raisonnable de suprimer ces fichiers... dans 5 minutes.... j'ai absolument besoin de mon PC ce soir qu'en pensez vous? je vs en supli aidez moi sino ordicide ce soir. merci infiniment d'avance
Configuration: Windows XP
Internet Explorer 6.0

70 réponses

  1. Contributeur sécurité
    supprime ce qu'AVG trouvera.
    0
    1. je t'envoi le rapport dés qu'il est finni mais déja il me dit 39 cookies... je suppose que je dois les supprimer....
      0
      1. Contributeur sécurité
        ok bon on verra la suite demain...
        a demain.
        0
        1. on a fait plusieurs manip depuis j'en lance un cette nuit
          0
          1. Contributeur sécurité
            le rapport smitfraudfix ne donne rien.
            as tu fais un scan complet avec AVG anti-spyware ??
            0
            1. message destiné uniquement ( la langue employée par un président américain mort) à JFK:

              hello I 'm here but without my fucking PC because my girlfriend work on (au ralenti certe mais qd même)

              que penses tu du rapport smitfraudfix?
              0
              1. SmitFraudFix v2.274

                Rapport fait à 21:27:47,68, 13/01/2008
                Executé à partir de C:\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\LEXBCES.EXE
                C:\WINDOWS\system32\LEXPPS.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\SearchIndexer.exe
                C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                C:\WINDOWS\system32\SearchProtocolHost.exe
                C:\WINDOWS\system32\cmd.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\UTILIS~1\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                "Source"="About:Home"
                "SubscribedURL"="About:Home"
                "FriendlyName"="Ma page d'accueil"

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                IEDFix.exe by S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Broadcom 802.11a/b/g WLAN - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.1.1
                DNS Server Search Order: 0.0.0.0

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{8E66FEA3-840C-4D30-AC0F-21BD11D2833F}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{8E66FEA3-840C-4D30-AC0F-21BD11D2833F}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS2\Services\Tcpip\..\{8E66FEA3-840C-4D30-AC0F-21BD11D2833F}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin

                merci

                je serai devant mon PC à partir de 19 heures
                0
                1. Contributeur sécurité
                  Télécharge SmitfraudFix de S!Ri, balltrap34 et moe31

                  http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                  Dézippe le puis

                  * Installe le à la racine de C

                  Tu crees un nouveau dossier, via clic droit "créer /nouveau dossier que tu nommes SmitfraudFix --> C:\SmitfraudFix

                  Regarde un exemple a E ) « Faire un répertoire dédié » https://forum.pcastuces.com/sujet.asp?f=25&s=3902

                  * double clic sur l'exe pour le décompresser et lancer le fix.
                  Utilisation ----- option 1 - Recherche :
                  * Double clique sur smitfraudfix.cmd
                  * Sélectionne 1 pour créer un rapport des fichiers responsables de l'infection.
                  * Poste le rapport ici
                  je regarderais ca demain...
                  0
                  1. par contre en fouillant un peu, dansle fichier arguments de genproc ya:

                    ~~ Arguments ~~

                    # Détections 13/01/2008 20:45:47,04 - C:\Documents and Settings\Utilisateur\Bureau\GenProc\outil

                    # Détections 13/01/2008 20:59:10,87 - C:\Documents and Settings\Utilisateur\Bureau\GenProc\outil
                    0
                    1. si le rapport me dit texto: [2] aucune infection caractéristique trouvée
                      0
                      1. Contributeur sécurité
                        tu n'as pas de rapport dans ton bloc note "genproc.txt" ??
                        0
                        1. aucune infection caractéristique trouvée
                          0
                          1. Contributeur sécurité
                            on va essayer ca:
                            télécharge genproc ici:http://www.alt-shift-return.org/Info/GenProc-HowTo.html
                            0
                            1. ca y est tt est à jour mais ça rame encore!!!!!!!!!!!!!!!!

                              je vien d'aller faire un tour ds le gestionnaire de taches: l'UC est tjs au tour de 40 pour cent...
                              0
                              1. Contributeur sécurité
                                apparement ton windows n'est pas a jour :Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                0
                                1. je suis en train de les faire tu crois que le problème viendrai de la?
                                  0
                                  1. ça rame moins mais les fichiers médias st tjs saccadés
                                    0
                                    1. Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 17:52, on 13/01/2008
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\LEXBCES.EXE
                                      C:\WINDOWS\system32\LEXPPS.EXE
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                      C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                      C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\SearchIndexer.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                      C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                                      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                      C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                                      C:\WINDOWS\system32\wuauclt.exe
                                      C:\Documents and Settings\Utilisateur\Bureau\test.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: (no name) - {ABCC12B6-C924-4BAB-9558-AA736E5D2E51} - C:\WINDOWS\system32\sstqp.dll (file missing)
                                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE RÉSEAU')
                                      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                                      O4 - Global Startup: BTTray.lnk = ?
                                      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                      O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
                                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                      O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                      O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
                                      O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
                                      O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                                      0
                                      • 1
                                      • 2
                                      • 3
                                      • 4