Comment supprimer Trojan.Exploit.Java.Gimsh.A

Résolu
Bonjour,

Comment puis-me débarasser de Trojan.Exploit.Java.Gimsh.A, il a été trouvé par le scan en ligne de bitdefendeur mais il n'a pas pu être
supprimer!
J'ai un besoin urgent de remettre mon pc au propre car je suis étudiante et j'ai un mémoire à taper en quelques jours mais mon pc rame trop!
Aider moi s'il vous plait,

Merci d'avance.
Configuration: Windows XP
Internet Explorer 7.0

22 réponses

Résumé de la discussion

Le Trojan Exploit.Java.Gimsh.A détecté par un balayage Bitdefender persiste malgré la suppression et entraîne des ralentissements sur Windows XP. Plusieurs intervenants recommandent des étapes manuelles ciblant le cache Java et des emplacements système, et l’identification possible d’un exécutable malveillant tel que sp_rsser.exe. D'autres proposent des outils spécialisés comme HijackThis, CCleaner, AVG Anti-Spyware, ou Spyware Terminator et des ressources en ligne pour guider les procédures de nettoyage, mises à jour et rapports. Une remarque récurrente indique aussi que la suppression peut échouer malgré un antivirus, suggérant de vérifier les paramètres, drivers et connexions réseau ou d’envisager des alternatives de nettoyage.

Bobot (l’IA à votre service)
  1. Contributeur
    Installe BitDefender Pro Plus, fait un scan complet de ton PC APRES avoir fait une mise à jour de la base de donnée virale
    De plus, vu le nom c'est pas un gros virus, c'est un trojan fait en java
    1. bonsoir gny,

      je te suggére de visiter ce site trés performant . enregistres toi et pose ton probléme a malékal .

      http://www.malekal.com/

      si tu as un souci reviens nous voir
      1. Contributeur sécurité
        bonsoir

        pourquoi l'envoyer sur un autre forum ? on n'est pas capable d'aider ici ???

    2. Salut,

      Comment ce fait-il que je ne trouve pas ce produit sur le site officiel de BitDefender?
      1. Contributeur
        http://download.bitdefender.com/windows/desktop/antivirus/final/fr/bitdefender_antivirus_2008.exe
    3. Contributeur sécurité
      et si on passait à qq chose de concret

      * Télécharge HijackThis et poste le rapport stp

      http://pchelpbordeaux.free.fr/logiciels.html
      Tutorial
      http://pchelpbordeaux.free.fr/tuto.html
      Démo en image (merci balltrap)
      demo hijackenregistrement http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif
      http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

      et

      * Télécharge CCleaner.

      https://www.pcastuces.com/logitheque/ccleaner.htm

      Installe le dans un répertoire dédié.

      Décoche pendant l'installation

      --- les deux cases "Ajouter l'option ... "

      --- Contrôler les mises à jour

      --- Ajouter la Barre d'Outils Yahoo! CCleaner

      * Lance Ccleaner pour un nettoyage complet.

      ------

      * télécharge AVG Anti-Spyware (ewido)

      https://www.avg.com/en-ww/free-antivirus-download

      * tu l'installes

      * lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

      puis

      Lance AVG Anti-Spyware

      Clique sur le bouton Analyse (de la barre d'outils)

      puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

      Puis sur l'onglet Paramètres,
      sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.

      Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

      A la fin du scan, choisis l'option 3

      "Appliquer toutes les actions " en bas.

      Clique sur "Enregistrer le rapport".

      Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

      Poste le.

      1. Merci, de toute façon je fais uniquement appel a CCM !

        Voici le rapport Hijackthis, et je continue la marche à suivre que vous m'avez indiquée Philae83.

        Logfile of HijackThis v1.99.1
        Scan saved at 00:46:31, on 09/09/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16441)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\Spyware Terminator\sp_rsser.exe
        C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\Daghari\Bureau\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gny95.spaces.live.com//PhotoUpload/MsnPUpld.cab
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://securite.neuf.fr/Ols/fscax.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{6B4A1C52-EADF-43D9-8CD8-95242052FAF2}: NameServer = 86.64.145.140,84.103.237.140
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
        O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
        O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
        1. Re,

          CCleaner ok, et voici le rapport ewido :

          ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 01:49:13 09/09/2007

          + Résultat de l'analyse:

          C:\Documents and Settings\Daghari\Cookies\daghari@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.

          Fin du rapport
          1. Contributeur sécurité
            bonjour,

            de rapide passage pour le moment

            as tu conservé le rapport de scan de bitdefender ?

            si oui poste le stp si non refait un scan en ligne et poste le rapport

            1. Bonjour,

              Oui effectiviement je l'ai gardé, le voici:

              BitDefender Online Scanner

              Rapport d'analyse généré à: Tue, Sep 04, 2007 - 00:50:50

              Voie d'analyse: C:\;D:\;F:\;G:\;H:\;I:\;J:\;K:\;

              Statistiques

              Temps
              03:55:17

              Fichiers
              223067

              Directoires
              5321

              Secteurs de boot
              4

              Archives
              6887

              Paquets programmes
              19269

              Résultats

              Virus identifiés
              1

              Fichiers infectés
              1

              Fichiers suspects
              0

              Avertissements
              0

              Désinfectés
              0

              Fichiers effacés
              1

              Info sur les moteurs

              Définition virus
              760994

              Version des moteurs
              AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)

              Analyse des plugins
              14

              Archive des plugins
              38

              Unpack des plugins
              6

              E-mail plugins
              6

              Système plugins
              1

              Paramètres d'analyse

              Première action
              Désinfecté

              Seconde Action
              Supprimé

              Heuristique
              Oui

              Acceptez les avertissements
              Oui

              Extensions analysées
              *;

              Excludez les extensions

              Analyse d'emails
              Oui

              Analyse des Archives
              Oui

              Analyser paquets programmes
              Oui

              Analyse des fichiers
              Oui

              Analyse de boot
              Oui

              Fichier analysé
              Statut

              C:\Documents and Settings\Daghari\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\game.class-506f6b50-19a2f9dd.class
              Infecté par: Trojan.Exploit.Java.Gimsh.A

              C:\Documents and Settings\Daghari\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\game.class-506f6b50-19a2f9dd.class
              Echec de la désinfection

              C:\Documents and Settings\Daghari\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\game.class-506f6b50-19a2f9dd.class
              Supprimé
              1. Contributeur sécurité
                bonjour,

                je constate tout de même que le trojan en question est sensé avoir été supprimé par bitdefender.
                pourquoi dis tu qu'il ne l'a pas été ?

                dans l'attente de ta réponse

            2. salut philae83,

              je ne doute pas de tes compétences mais visiblement tu es en train de ra mer dans tes explications.

              je te suggére aussi de visiter le site de Malékal et tu veras que le procédures sont plus pertinentes que les tiennes .
              1. Contributeur sécurité
                bonjour sonny1024

                je ne doute pas de tes compétences mais visiblement tu es en train de ra mer dans tes explications.


                c'est à dire >? j'ai pourtant pas l'impression de ramer comme tu dis, je suis une ligne logique de conduite pour savoir où se trouve son problème.

                je te suggére aussi de visiter le site de Malékal et tu veras que le procédures sont plus pertinentes que les tiennes .
                

                c'est à moi que tu suggères ?
                parce que sincèrement je n'attends pas après toi pour me suggérer un site à consulter, et encore moins celui de malekal que tous les helpers connaissent.

                Il n'y a jamais de raccourci vers les endroits qui en valent la peine - Beverley Sills
                1. Je suppose qu'il n'a pas été complètement supprimer car j'ai effectuer le scan 2 fois, et la seconde fois il était toujours présent.
                  d'ailleurs c'est le 2ème rapport que je t'ai posté. Enfin il a été supprimé mais pas desinfecté, de toute façon aucune amelioration de l'etat de mon pc.
                  1. Contributeur sécurité
                    re

                    je ne fais que lire le rapport du scan de bitdefender il est écrit SUPPRIME

                    va voir dans ton cache java

                    * Assure toi d'avoir accès à tous les fichiers

                    -démarrer

                    -poste de travail ou autre dossier

                    -menu outils

                    -options de dossier

                    -onglet affichage

                    puis

                    - activer la case : Afficher les fichiers et dossiers cachés

                    - désactiver la case : Masquer les extensions des fichiers dont le type est connu

                    - désactiver la case : Masquer les fichier protégés du système d'exploitation

                    Puis - Appliquer

                    puis

                    C:\Documents and Settings\Daghari\Application Data\Sun\Java\Deployment\cache\javapi\v1.0----------supprime tout le contenu

                    tu parles de l'état de ton pc, mais tu ne dis rien de +.

                    * Télécharge le script "Silent Runners"

                    clic droit > "enregistrer sous" (et non pas clic gauche) sur le lien suivant :
                    https://www.silentrunners.org/Silent%20Runners.vbs
                    clique ensuite 2 fois sur "yes"
                    Laisse lui le temps de faire son analyse (compte une minute, montre en main)

                    poste le rapport généré qui se trouve dans le meme dossier que Silent Runners...

                    Si ton antivirus s'affole, autorise ce script. Ou au pire, désactive-le juste le temps du téléchargement et du scan. Ce script n'est pas dangereux.

                    1. Bonjour,

                      Désolée de n'avoir pas répondu plus tôt mais j'avais trop de travail avec mes exams.
                      Bref, le soucis avec mon PC c'est qu'il est devenu extra extra lent, que ce soit sur le net ou même en dehors.

                      Voici le rapport demandé:

                      "Silent Runners.vbs", revision 52, https://www.silentrunners.org/
                      Operating System: Windows XP SP2
                      Output limited to non-default values, except where indicated by "{++}"

                      Startup items buried in registry:
                      ---------------------------------

                      HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
                      "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
                      "WinPatrol" = "C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe" ["BillP Studios"]
                      "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" ["ALWIL Software"]
                      "!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["GRISOFT s.r.o."]

                      HKLM\Software\Microsoft\Active Setup\Installed Components\
                      >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
                      \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
                      -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
                      \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
                      {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
                      -> {HKLM...CLSID} = "Windows Live Sign-in Helper"
                      \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                      "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                      -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
                      \InProcServer32\(Default) = "deskpan.dll" [file not found]
                      "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                      -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
                      "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
                      -> {HKLM...CLSID} = "DesktopContext Class"
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
                      "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
                      -> {HKLM...CLSID} = "NVIDIA CPL Extension"
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
                      "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
                      -> {HKLM...CLSID} = "Desktop Explorer"
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
                      "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
                      -> {HKLM...CLSID} = (no title provided)
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
                      "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
                      -> {HKLM...CLSID} = "nView Desktop Context Menu"
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
                      "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
                      -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
                      \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
                      "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
                      -> {HKLM...CLSID} = "Mes dossiers de partage"
                      \InProcServer32\(Default) = "C:\Program Files\Windows Live\Messenger\fsshext.8.5.1235.0517.dll" [MS]
                      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
                      -> {HKLM...CLSID} = "WinRAR"
                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                      "{A155339D-CCCD-4714-85EB-3754B804C9DF}" = "a-squared Free Context Menu Shell Extension"
                      -> {HKLM...CLSID} = "a-squared Free Context Menu"
                      \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL" ["Emsi Software GmbH"]
                      "{BD88A479-9623-4897-8546-BC62B9628F44}" = "SPTHandler"
                      -> {HKLM...CLSID} = "SPTHandler"
                      \InProcServer32\(Default) = "C:\Program Files\Spyware Terminator\sptcontmenu.dll" ["Crawler.com"]
                      "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
                      -> {HKLM...CLSID} = "avast"
                      \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                      "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
                      -> {HKLM...CLSID} = "Microsoft Office Outlook"
                      \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\OFFICE11\MLSHEXT.DLL" [MS]
                      "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
                      -> {HKLM...CLSID} = "Outlook File Icon Extension"
                      \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\OFFICE11\OLKFSTUB.DLL" [MS]
                      "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                      -> {HKLM...CLSID} = (no title provided)
                      \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
                      <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
                      -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["GRISOFT s.r.o."]

                      HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
                      "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
                      -> {HKLM...CLSID} = "WPDShServiceObj Class"
                      \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

                      HKLM\System\CurrentControlSet\Control\Session Manager\
                      <<!>> "BootExecute" = "autocheck autochk *"| [file not found]

                      HKLM\Software\Classes\PROTOCOLS\Filter\
                      <<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
                      -> {HKLM...CLSID} = (no title provided)
                      \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

                      HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
                      {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
                      -> {HKLM...CLSID} = "PDF Shell Extension"
                      \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

                      HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                      avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                      -> {HKLM...CLSID} = "avast"
                      \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                      AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
                      -> {HKLM...CLSID} = "CContextScan Object"
                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["GRISOFT s.r.o."]
                      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                      -> {HKLM...CLSID} = "WinRAR"
                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                      HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
                      AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
                      -> {HKLM...CLSID} = "CContextScan Object"
                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["GRISOFT s.r.o."]
                      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                      -> {HKLM...CLSID} = "WinRAR"
                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                      HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                      a2FreeContMenu\(Default) = "{A155339D-CCCD-4714-85EB-3754B804C9DF}"
                      -> {HKLM...CLSID} = "a-squared Free Context Menu"
                      \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL" ["Emsi Software GmbH"]
                      avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                      -> {HKLM...CLSID} = "avast"
                      \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                      -> {HKLM...CLSID} = "WinRAR"
                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                      HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
                      a2FreeContMenu\(Default) = "{A155339D-CCCD-4714-85EB-3754B804C9DF}"
                      -> {HKLM...CLSID} = "a-squared Free Context Menu"
                      \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL" ["Emsi Software GmbH"]
                      SPTContMenu\(Default) = "{BD88A479-9623-4897-8546-BC62B9628F44}"
                      -> {HKLM...CLSID} = "SPTHandler"
                      \InProcServer32\(Default) = "C:\Program Files\Spyware Terminator\sptcontmenu.dll" ["Crawler.com"]

                      Group Policies {policy setting}:
                      --------------------------------

                      Note: detected settings may not have any effect.

                      HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

                      "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
                      {Prevent access to registry editing tools}

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

                      "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
                      {Shutdown: Allow system to be shut down without having to log on}

                      "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
                      {Devices: Allow undock without having to log on}

                      Active Desktop and Wallpaper:
                      -----------------------------

                      Active Desktop may be disabled at this entry:
                      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                      Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
                      HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
                      "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

                      Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
                      HKCU\Control Panel\Desktop\
                      "Wallpaper" = "C:\Documents and Settings\Daghari\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

                      Startup items in "Daghari" & "All Users" startup folders:
                      ---------------------------------------------------------

                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                      "Lancement rapide d'Adobe Reader" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]

                      Winsock2 Service Provider DLLs:
                      -------------------------------

                      Namespace Service Providers

                      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                      000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                      000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                      000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                      Transport Service Providers

                      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                      0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                      %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
                      %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

                      Toolbars, Explorer Bars, Extensions:
                      ------------------------------------

                      Explorer Bars

                      HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

                      HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Rechercher"
                      Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
                      InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL" [MS]

                      Running Services (Display Name, Service Name, Path {Service DLL}):
                      ------------------------------------------------------------------

                      avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" ["ALWIL Software"]
                      avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" ["ALWIL Software"]
                      avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
                      avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
                      AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["GRISOFT s.r.o."]
                      Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS]
                      Service Messenger Sharing Folders USN Journal Reader, usnjsvc, ""C:\Program Files\Windows Live\Messenger\usnsvc.exe"" [MS]
                      Spyware Terminator Realtime Shield Service, sp_rssrv, ""C:\Program Files\Spyware Terminator\sp_rsser.exe"" ["Crawler.com"]
                      Windows Driver Foundation - User-mode Driver Framework, WudfSvc, "C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup" {"C:\WINDOWS\System32\WUDFSvc.dll" [MS]}

                      Print Monitors:
                      ---------------

                      HKLM\System\CurrentControlSet\Control\Print\Monitors\
                      EPSON Stylus CX6600 Series 2KMonitor5E\Driver = "E_FLM9EE.DLL" ["SEIKO EPSON CORPORATION"]
                      Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
                      PDFCreator\Driver = "pdfcmnnt.dll" [null data]

                      ---------- (launch time: 2007-09-15 15:45:58)
                      <<!>>: Suspicious data at a malware launch point.

                      + This report excludes default entries except where indicated.
                      + To see *everywhere* the script checks and *everything* it finds,
                      launch it from a command prompt or a shortcut with the -all parameter.
                      + To search all directories of local fixed drives for DESKTOP.INI
                      DLL launch points, use the -supp parameter or answer "No" at the
                      first message box and "Yes" at the second message box.
                      ---------- (total run time: 589 seconds, including 5 seconds for message boxes)

                      Merci de ton aide
                      1. Contributeur sécurité
                        bonsoir,

                        merci pour silent runner,

                        as tu été voir

                        C:\Documents and Settings\Daghari\Application Data\Sun\Java\Deployment\cache\javapi\v1.0----------supprime tout le contenu

                        où en es tu ? toujours pareil ?

                        1. Bonjour,

                          je suis bien aller voir C:\Documents and Settings\Daghari\Application Data\Sun\Java\Deployment\cache\javapi\v1.0
                          mais le dossier cache est vide.
                          Quant à mes problèmes toujours pareil, mon pc est toujours aussi lent. petit exemple: pour me connecter à ccm il m'a fallut montre en main
                          4,30 minutes! c'est vraiment très énervant!

                          Merci
                          1. Contributeur sécurité
                            bonsoir

                            es tu certain que le problème de connexion ne viendrait pas de ton FAI ?

                            as tu testé la vitesse de ta connexion ?

                            1. Bonsoir,

                              Je ne pense pas, mais la lenteur de mon PC n'est pas que pour Internet c'est pour tout ce que je peux faire avec mon PC!
                              ex: Réaliser un doc Word, excel, ou encore écouter de la musique, ....

                              par contre mon UC est toujours utilisée à 100% même quand aucune application ne tourne!
                              Du coup mon UC fait un bruit hallucinant dès qu'elle est en route!
                              1. Contributeur sécurité
                                bonsoir,
                                par contre mon UC est toujours utilisée à 100% même quand aucune application ne tourne! 


                                quel est le processus qui te bouffe ton uc ?
                                regarde dans ctrl+alt+supp----onglet processus

                                1. Contributeur sécurité
                                  c'est Spyware terminator. Si tu vois qu'il continue à t'ennuyer ainsi, il va te falloir laisser tomber avec lui.
                                  • 1
                                  • 2