Alors depuis hier après midi, sans avoir fait quoi que ce soit d'inhabituel (sauf laisser mon petit cousin de 6 ans sur l'ordi, internet allumer, sans que je sois là durant quelques heures) j'ai un petit problème avec l'explorateur windows...
Alors le soir j'arrive tout fonctionne, je joue un jeu et là le jeu se plante, je redémarre le PC et puis le processus explorer.exe démarre, s'arrête, démarre, s'arrête, puis s'arrête... totalement.
J'ai essayé de relancer le processus de part le gestionnaire de tâche mais, le processus se lance puis s'arrête après quelques seconde (c'est grâce à ces quelques seconde que j'ai pu me connecter et lancer certaine recherche à ce sujet, mais en vain.) En effet, je précise que le processus s'arrête sans message d'erreur, et en mode sans échec le processus s'arrête aussi. Ce qui me pose un sérieux problème ; j'ai pu lancer une analyse avec mon antivir la nuit dernière, ce qui m'étonne c'est qu'il y a eu 1 seule détection, qui fut mis en quarantaine...
(cette démarche d'analyse n'a pas pu etre fait en mode sans échec, le temps que le processus explorer.exe reste en fonction n'est que d'une fraction seconde)...
Alors j'ai réussi tout juste a click sur le raccourci d'hijackthis..je vous envoie le rapport de mon antivir et d'hijackthis...
PS: On m'a déjà averti pour l'illégalité, et les problèmes que peut engendré les crack de jeu...et puis je ne pense pas que ce soit l'un d'eux puisque la dernière installation n'a pas encore provoqué de problème visible et si encombrant que celui-là...
PS.Bis : Hier j'ai téléchargé un petit jeu de tetris free mon petit cousin, bon j'ai désinstaller...enfin voilà un autre info qui pourrait être utile...
Avira AntiVir Personal
Report file date: mercredi 9 juillet 2008 22:53
Scanning for 1399497 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: HIGHTECH
Version information:
BUILD.DAT : 8.1.0.308 16478 Bytes 28/05/2008 17:03:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 25/04/2008 14:58:00
AVSCAN.DLL : 8.1.1.0 53505 Bytes 25/04/2008 14:58:00
LUKE.DLL : 8.1.2.9 151809 Bytes 25/04/2008 14:58:01
LUKERES.DLL : 8.1.2.1 12033 Bytes 25/04/2008 14:58:01
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:44:41
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 14:56:06
ANTIVIR2.VDF : 7.0.5.51 273408 Bytes 04/07/2008 14:56:27
ANTIVIR3.VDF : 7.0.5.81 281600 Bytes 09/07/2008 14:49:44
Engineversion : 8.1.0.64
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/04/2008 14:58:02
AESCRIPT.DLL : 8.1.0.46 283002 Bytes 04/07/2008 14:56:56
AESCN.DLL : 8.1.0.22 119157 Bytes 21/06/2008 14:48:45
AERDL.DLL : 8.1.0.20 418165 Bytes 25/04/2008 14:58:02
AEPACK.DLL : 8.1.1.6 364918 Bytes 21/06/2008 14:48:42
AEOFFICE.DLL : 8.1.0.20 192891 Bytes 21/06/2008 14:48:36
AEHEUR.DLL : 8.1.0.35 1298806 Bytes 04/07/2008 14:56:52
AEHELP.DLL : 8.1.0.15 115063 Bytes 30/05/2008 14:49:37
AEGEN.DLL : 8.1.0.29 307573 Bytes 21/06/2008 14:48:18
AEEMU.DLL : 8.1.0.6 430451 Bytes 08/05/2008 14:39:25
AECORE.DLL : 8.1.0.32 168311 Bytes 04/07/2008 14:56:33
AVWINLL.DLL : 1.0.0.7 14593 Bytes 25/04/2008 14:58:00
AVPREF.DLL : 8.0.0.1 25857 Bytes 25/04/2008 14:58:00
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 10:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 25/04/2008 14:58:00
AVARKT.DLL : 1.0.0.23 307457 Bytes 25/04/2008 14:57:59
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 25/04/2008 14:57:59
SQLITE3.DLL : 3.3.17.1 339968 Bytes 25/04/2008 14:58:01
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 25/04/2008 14:58:01
NETNT.DLL : 8.0.0.1 7937 Bytes 25/04/2008 14:58:01
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 25/04/2008 14:57:53
RCTEXT.DLL : 8.0.32.0 86273 Bytes 25/04/2008 14:57:53
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: mercredi 9 juillet 2008 22:53
The scan of running processes will be started
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Azureus.exe' - '1' Module(s) have been scanned
Scan process 'DAP.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'wceemiy.exe' - '1' Module(s) have been scanned
Scan process 'MemOptimizer.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'CursorXP.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'snmp.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'svdhost.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
34 processes with 34 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '27' files ).
Starting the file scan:
Begin scan in 'C:\' <DivX>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Propriétaire\Mes documents\Azureus Downloads\TuneUp\TuneUp Utilities 2008 v7.0.8002\keygen.exe
[DETECTION] Is the Trojan horse TR/PSW.LdPinch.uij
[NOTE] The file was moved to '48ee840b.qua'!
C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP104\A0046135.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Agent.VB.P Backdoor server programs
[NOTE] The file was moved to '48a58fc1.qua'!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
End of the scan: jeudi 10 juillet 2008 08:42
Used time: 9:48:46 min
The scan has been done completely.
11228 Scanning directories
484552 Files were scanned
2 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
484550 Files not concerned
4634 Archives were scanned
2 Warnings
2 Notes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:35:48, on 10/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\svdhost.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\avira\antivir personaledition classic\avcenter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\system32\control.exe
C:\WINDOWS\system32\rundll32.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.co...earch_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Sound] svdhost.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\Propriétaire\lsass.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe -s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [wceemiy] c:\documents and settings\propriétaire\local settings\application data\wceemiy.exe wceemiy
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP Premium\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP Premium\dapextie.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP Premium\dapextie2.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.ka...can_unicode.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zon...ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4229D580-7E9B-44D8-9B00-9894079C64A8}: NameServer = 217.175.160.168 217.175.160.12
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 6769 bytes
Ce message a été modifié par Reukin - 10 juillet 2008 - 08:43 .

Aide







