Vundo ou autre chose?

lachoukrate -  
 Eliane -
Bonjour,
Depuis deux jours j'ai lu un paquet de postes, mais malgré les aides que ca m'a apporté, j'ai pas réussi à trouver mon probleme exact. J'ai installé spybot, ccleaner, hijackthis, avg spyware. Mais mon probleme vient d'un probleme de "crc check failed", mon antivir ne marche plus, soit une mauvaise manip de ma part, soit un virus... Lorsque j'essaie de l'enlever ou de le réinstaller, il veut pas!!! J'ai essayé d'installer avg antivirus, mais lors de l'installation il me dit une erreur est survenue, et s'arrete. En gros je n'ai plus d'antivirus opérationnel.
Tout a l'heure une page antivirus 2009 signé windows xp, s'est ouverte sans que je l'autorise et m'a fait un scan en me disant que j'avais : spyware.iemonster.b, zlob.pornadvertiser.xplisit (c'est sexuel??? :-)) et trojan.infostealer.banker.s. Je sens que mon ordi va me lacher :-( Je n'ai pas de disque d'install de windows (2000) et j'aimerai éviter le formatage.
Je suis pas douée en informatique, j'apprends sur le tas. Mais grace à toutes vos réponses je commence à etre callée en désinfection d'ordi, mais pas suffisamment hélas pour sauver le mien.
J'ai des logs de hijackthis et spybot.
Merci à celui qui pourra m'aider
et merci à tous pour votre aide si précieuse meme si c'est pas en direct, j'ai compris énormément de choses en lisant vos réponses...

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 16:41:23 05/01/2009

+ Résultat de l'analyse:



HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignoré.
HKU\S-1-5-21-57989841-602162358-682003330-1000\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@247realmedia[2].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@2o7[2].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@autoscout24.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@electronicarts.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@himedia.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@notrefamille.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@parship.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@veohnetwork.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adbrite[2].txt -> TrackingCookie.Adbrite : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@dynamic.media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adtech[2].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@adtech[1].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@advertising[1].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@advertising[2].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@bluestreak[2].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@casinotropez[1].txt -> TrackingCookie.Casinotropez : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@com[1].txt -> TrackingCookie.Com : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@www.etracker[1].txt -> TrackingCookie.Etracker : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@fastclick[2].txt -> TrackingCookie.Fastclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@hitbox[1].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ivwbox[2].txt -> TrackingCookie.Ivwbox : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@search.live[1].txt -> TrackingCookie.Live : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ie.search.msn[1].txt -> TrackingCookie.Msn : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@ie.search.msn[2].txt -> TrackingCookie.Msn : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@overture[1].txt -> TrackingCookie.Overture : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@specificclick[2].txt -> TrackingCookie.Specificclick : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@statcounter[2].txt -> TrackingCookie.Statcounter : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@toplist[1].txt -> TrackingCookie.Toplist : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cms.trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@aem.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@agircarrco.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@aimfar.solution.weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@boursoramabanque.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cetelem.solution.weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@cnam.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@dolcegusto16avril11juin.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@francecredit2.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@interhome.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@intermarche.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@nespresso.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@samsung.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@sanofi.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@vivelledop.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@banquepopulaire.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@boursoramabanque.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@intermarche.solution.weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Local Settings\Temp\Cookies\chouchouk@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@content.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\chouchouk\Cookies\chouchouk@zedo[1].txt -> TrackingCookie.Zedo : Ignoré.


Fin du rapport



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:40:18, on 05/01/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\WINNT\system\msddll.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ScsiAccess.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\QuickTime\qttask.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINNT\system32\sysmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINNT\system32\sistray.exe
C:\Program Files\MultiRes\MultiRes.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jeuxvideo-flash.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%\Mctray.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINNT\system32\sysmgr.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: MultiRes.lnk = C:\Program Files\MultiRes\MultiRes.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINNT\system32\sistray.exe
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Events Log (Event) - Unknown owner - C:\WINNT\system32\drivers\csrss.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: m43158.exe - Unknown owner - \\82.253.79.183\Admin$\m75034.exe (file missing)
O23 - Service: m46247.exe - Unknown owner - \\82.253.79.183\Admin$\m53463.exe (file missing)
O23 - Service: McAfee Security Agent Taskbar Extension. - Unknown owner - C:\WINNT\Mctray.exe (file missing)
O23 - Service: msddll - Unknown owner - C:\WINNT\system\msddll.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: ptssvc - Unknown owner - D:\Kodak EasyShare software\bin\ptssvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\system32\ScsiAccess.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VMwareService - Unknown owner - C:\WINNT\system\VMwareService.exe
O23 - Service: Windows Spool Services (WinSpoolSvc) - Unknown owner - C:\WINNT\system32\csrsc.exe (file missing)

282 réponses

lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
ca y est je l'ai sur le cd d'install dans I386
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
je n'arrive pas a passer c:\winnt\system32 tout seul au scan. Il me demande un fichier
Je fais quoi? Quand je passe le fichier userinit.exe au scan, il me dit toujours virut.q
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Re,

si tu ne peux pas passer un répertoire, passe la partition C: (comme tu as déjà fait).

Pour que je comprenne ta structure :

le lecteur de CD est externe et branché sur l'USB ?

Le disque système (W2000) est interne (ou externe et branché à une peise USB) ?

=================

sur le CD d'install, tu l'as en .exe ou en .ex_ ?
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
en fait j'ai une mini tour asus terminator P4 que m'a donné un de mes eleves(merci) avec un disque dur de 7go et un lecteur cd. MAis pour le scan d'hier, j'avais branché ma clé usb et mon autre disque dur interne en rab de mon ancien ordi (10go je crois et en xp à la base me semble t-il), donc il me fallait débrancher mon lecteur de cd. Le systeme est sur le DD interne de 7 go. Celui d'origine de la tour.

"sur le CD d'install, tu l'as en .exe ou en .ex_ ? " -> je l'ai en .ex_
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
C'est sur avp tool que tu veux que je fasse le scan de la partition? La je sais refaire
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Re,

oui, c'est sur AVP Tool.

Sur la partition ou mieux sur un répertoire si il veut bien.
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
bon avp tool tourne que sur c:, mais j'en suis toujours qu'à 8% et 7 détections dont 6 de virut.q et un trojan.
En attendant j'ai trouvé un topic dont voici le lien : http://www.commentcamarche.net/forum/affich 8818332 win32 virut, ou ils parlent de rmvirut, et d'un tuto de malekal, j'ai pas encore suivi le lien... Je ne sais pas ce que ca vaut, je te laisse en juger, en tout cas il est écrit que souvent c'est le formatage qui est le plus efficace... Ouiiiinh. Plus de trois semaines de désinfection pour devoir finir par un formatage, ce serait trop dur ca... On va trouver, n'est ce pas ???!!!
Bon je crois que je vais t'abandonner pour ce soir, j'arrive plus à me réveiller le matin, et demain je repars sur paris pour bosser tout le we, mais demain matin je verrai si tu a laissé des directives.
Bonne nuit lyonnais, encore 5 minutes et je coupe...
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Re,

ma directive, est de relancer une deuxième analyse de AVP tool dans la foulée, sans rebooter l'ordi.

On fera le point sur le vu du rapport de ce 2ème passage.
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Re,

pas de défaitislme.

1) as tu un fichier userinit.ex_ sur un répertoire ?

2) essaye de réinstaller antivi

3) relance kaspersky AV sur c:\winnt\system32
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
voici le rapport avp

detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fp98swin.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpadmcgi.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpcount.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\fpremadm.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\freecell.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\gameenum.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\grpconv.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\help.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hh.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\hostname.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\htimage.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn1.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwconn2.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwrmind.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\icwtutor.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ie4uinit.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ieshwiz.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexplore.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iexpress.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisreset.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iisrstas.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\iissync.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imagemap.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpmgr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\imejpuex.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetinfo.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetmgr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\inetwiz.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\internat.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipconfig.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipsecmon.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ipxroute.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\irftp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\isignup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakimg.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\kodakprv.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\label.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lights.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\LLSSRV.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lnkstub.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\locator.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lodctr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\logagent.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpq.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lpr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\lsass.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\magnify.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\makecab.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migisol.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migpwd.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\migregdb.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mmc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mnmsrvc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mobsync.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mofcomp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mountvol.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplay32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mplayer2.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mpnotify.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mq1sync.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqbkup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqexchng.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqmig.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mqsvc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mrinfo.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msdtc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mshta.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msiexec.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\MSIMN.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msinfo32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mspaint.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\msswchx.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstask.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mstinit.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mtstocom.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcload.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcloadw.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcpyrt.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwcsw32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwmdmsvc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwremind.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\mwssw32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\narrator.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nbtstat.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nddeapir.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\net1.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netdde.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netmon.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netsh.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\netstat.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\notepad.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nppagent.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nsisapi.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nslookup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntbackup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntdsutil.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntsd.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ntvdm.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\nwscript.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcad32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\odbcconf.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\OEMIG50.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\os2.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\os2srv.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\osk.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\packager.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pathping.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pax.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pentnt.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\perfmon.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pinball.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ping.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\print.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\progman.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\proquota.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\psxss.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pws.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\pwstray.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\qtest32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasadmin.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasautou.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasdial.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rasphone.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rcp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\recover.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regedit.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regedt32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regsvc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regsvr32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\regwiz.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\replace.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rexec.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\route.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\routemon.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsh.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsm.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsnotify.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rsvp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\runas.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\rundll32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\runonce.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\savedump.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\scardsvr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\scrcons.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\secedit.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\services.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sethc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setreg.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\setup50.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sfc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shmgrate.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shrpubw.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\shtml.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sigverif.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\skeys.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\smlogsvc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\smtp_regtrace.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sndrec32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sndvol32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\snmp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\snmptrap.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sol.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sort.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\spoolsv.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\stimon.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\stisvc.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\subst.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\svchost.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\syncapp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\syskey.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\sysocmgr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\systray.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\taskman.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\taskmgr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcmsetup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcpsvcs.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tcptest.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\telnet.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\themes.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntadmn.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntsess.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tlntsvr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\tracert.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\twunk_32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unlodctr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unregmp2.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\unsecapp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\ups.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\upwizun.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\userinit.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\utilman.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\vcmd.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\verclsid.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\verifier.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\w32tm.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WAB.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WABMIG.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wangimg.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wb32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wbemperm.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wbemtest.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\welcome.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wextract.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winhlp32.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winhstb.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\WINLOGON.EXE
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmgmt.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmine.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winmsd.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winrep.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wins.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\winver.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wordpad.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wpnpinst.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\write.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wscript.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wupdmgr.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\wzcsetup.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\dllcache\xcopy.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\drivers\KodakCCS.exe
detected: Trojan program Rootkit.Win32.Agent.jj File: C:\WINNT\system32\drivers\protect.sys
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\export\encinst.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\npp\nppagent.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\QuickTime\QTPluginInstaller.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\QuickTime\QuickTimeUpdateHelper.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Setup\wmpocm.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\mofcomp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\scrcons.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\unsecapp.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\wbem\wbemtest.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\Windows Media\Server\nsisapi.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\temp\0.EXE
detected: Trojan program Trojan.Win32.Agent.bicr File: C:\WINNT\temp\BN20.tmp


Events
------
Time Name Status Reason
---- ---- ------ ------


Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------


Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes


Quarantine
----------
Status Object Size Added
------ ------ ---- -----


Backup
------
Status Object Size
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
mauvaise nouvelle il n'a rien pu désinfecter.

Je ne comprends pas le terme répertoire

je t'envoie le début du rapport avp tool

Scan
----
Scanned: 125631
Detected: 891
Untreated: 886
Start time: 23/01/2009 01:08:45
Duration: 07:00:10
Finish time: 23/01/2009 08:08:55


Detected
--------
Status Object
------ ------
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\services.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.q File: C:\WINNT\system32\svchost.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\System32\WBEM\WinMgmt.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\system32\gcc.exe
not found: virus Virus.Win32.Virut.q File: C:\WINNT\services.exe
detected: virus Virus.Win32.Virut.q File: C:\WINNT\explorer.exe
detected: Trojan program Backdoor.Win32.Agent.acnq File: C:\ipasj.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstCCD.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCS.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCSFEMsi.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_0_8288de\Setup.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_0_893f41\Setup.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\CCS\CCSStop.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\Ksu\KSUStop.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\IDEUtil\SISIDE.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\process.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\reader_s.exe
quarantined: virus Heur.Virus.Generic (modification) File: C:\Documents and Settings\chouchouk\vfind.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\catchme.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\Cghtme.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\cliptext.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\download.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\ERUNT.EXE
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\FixPath.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\grep.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\isadmin.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\LS.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\MD5File.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\moveex.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\Process.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\procs.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\psservice.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\RestartIt!.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\sc.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\sed.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\SF.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\shutdown.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\Swreg.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\swsc.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\UnRAR.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\unzip.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\vfind.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\WINMSG.EXE
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\zip.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\SDFix\SDFix\apps\Replace\regedit.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-HGME0\is-HGME0.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-HGME0\minst.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-HGME0\startup.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\chouchouk\Bureau\Virus Removal Tool\is-HGME0\drivers\drvins32.exe
detected: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\Default User\reader_s.exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\0NAZKDG1\0032[1].exe
detected: Trojan program Backdoor.Win32.Small.hik File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\0NAZKDG1\abb[1].txt
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EFAXK1IJ\0032[1].exe
detected: Trojan program Trojan-Dropper.Win32.Agent.aevf File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EFAXK1IJ\ge[1].txt
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[1].exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[2].exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[3].exe
not found: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\EPWPCVM9\0032[4].exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\0032[1].exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\0032[2].exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\sev[1].exe
detected: virus Virus.Win32.Virut.q File: C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\Y9S1GBUR\sev[2].exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\catchme.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\dumphive.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\md5file.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\moveex.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\process.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\reboot.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\swreg.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\swsc.exe
detected: virus Virus.Win32.Virut.q File: C:\HaxFix\vfind.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\7-Zip\7z.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\7-Zip\7zG.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\launcher.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06\zipper.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Kodak\kodak_dr\inst_act.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Kodak\kodak_dr\KodakCCS.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Microsoft Shared\MSInfo\msinfo32.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Hewlett-Packard\Diagnostics\HPSysDig.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\HP\Digital Imaging\bin\HP Promotions\JourneySoftware\HPpromo.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\HP\Temp\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\HP\Temp\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzmsi01.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\HP\Temp\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzrcv01.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\HP\Temp\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\InstallShield Installation Information\{39345B45-A64A-4BA2-A235-F3632281A5A5}\Setup.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Internet Explorer\DW15.EXE
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Internet Explorer\IE Uninstall\w2kexcp.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\java-rmi.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\java.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\javacpl.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\javaw.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\keytool.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\kinit.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\klist.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\ktab.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\orbd.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\pack200.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\policytool.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\rmid.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\rmiregistry.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\servertool.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\ssvagent.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Java\jre1.6.0_07\bin\tnameserv.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak EasyShare software\bin\ptswia.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Kodak\Kodak Utilities\kodnotif.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Nokia\Connectivity Cable Driver\setupext.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Nokia\Nokia PC Suite 6\PCSyncLV.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\configimport.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\crashrep.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\gengal.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\msfontextract.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\msi-pkgchk.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\nsplugin.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\odbcconfig.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\pkgchk.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\scalc.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\senddoc.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\setofficelang.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\stclient_wrapper.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\swriter.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\uno.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\unopkg.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\python-core-2.3.4\bin\python.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\OpenOffice.org 2.4\program\python-core-2.3.4\lib\distutils\command\wininst.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\MSIMN.EXE
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\OEMIG50.EXE
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\setup50.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\WAB.EXE
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Outlook Express\WABMIG.EXE
detected: virus Virus.Win32.Virut.q File: C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\QuickTime\QTInfo.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\QuickTime\qttask.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\registrycleaner_en\RegCleaner.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Runtimeware.com\Sentinel2\SentinelLow.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\acldiag.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\apcompat.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\apmstat.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\browstat.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dcdiag.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\depends.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dfsutil.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dnscmd.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dsacls.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dsastat.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dskprobe.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\dumpchk.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\filever.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\gflags.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\kill.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\ksetup.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\ktpass.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\ldp.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\memsnap.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\movetree.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\msicuu.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\msizap.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\netdiag.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\netdom.exe
detected: virus Virus.Win32.Virut.q File: C:\Program Files\Support Tools\nltest.exe
detecte
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
je n'arrive pas a scanner le répertoire uniquement, d'ailleurs je suis pas sure de faire ce qu'il faudrait :-(

voici le rapport collectsysinfo, fait par avp, il n'a pas pu finir, je sais pas si ca peut etre utile


<AVZ_CollectSysInfo>
--------------------
Start time: 23/01/2009 09:39:05
Duration: 00:00:42
Finish time: 23/01/2009 09:39:47


<AVZ_CollectSysInfo>
--------------------
Time Event
---- -----
23/01/2009 09:39:08 Windows version: Microsoft Windows 2000, Build=2195, SP="Service Pack 4"
23/01/2009 09:39:08 System Restore: enabled
23/01/2009 09:39:08 >>>> Probable masking of executable file's name 5380 launchapplication.exe, real name - LaunchApplicati
23/01/2009 09:39:08 >>>> Probable masking of executable file's name 8496 head-22-10-10.exe, real name - head-22-10-10.e
23/01/2009 09:39:08 >>>> Probable masking of executable file's name 16000 servicelayer.exe, real name - ServiceLayer.ex
23/01/2009 09:39:10 1.1 Searching for user-mode API hooks
23/01/2009 09:39:10 Analysis: kernel32.dll, export table found in section .text
23/01/2009 09:39:10 Function kernel32.dll:FreeLibrary (200) intercepted, method ProcAddressHijack.GetProcAddress ->77E90897->61F041FC
23/01/2009 09:39:10 Hook kernel32.dll:FreeLibrary (200) blocked
23/01/2009 09:39:10 Function kernel32.dll:GetModuleFileNameA (317) intercepted, method ProcAddressHijack.GetProcAddress ->77E90AA8->61F040FB
23/01/2009 09:39:10 Hook kernel32.dll:GetModuleFileNameA (317) blocked
23/01/2009 09:39:10 Function kernel32.dll:GetModuleFileNameW (318) intercepted, method ProcAddressHijack.GetProcAddress ->77E90930->61F041A0
23/01/2009 09:39:10 Hook kernel32.dll:GetModuleFileNameW (318) blocked
23/01/2009 09:39:10 Function kernel32.dll:GetProcAddress (344) intercepted, method ProcAddressHijack.GetProcAddress ->77E90CF7->61F04648
23/01/2009 09:39:10 Hook kernel32.dll:GetProcAddress (344) blocked
23/01/2009 09:39:10 Function kernel32.dll:LoadLibraryA (486) intercepted, method ProcAddressHijack.GetProcAddress ->77E9026D->61F03C6F
23/01/2009 09:39:10 Hook kernel32.dll:LoadLibraryA (486) blocked
23/01/2009 09:39:10 >>> Functions LoadLibraryA - preventing AVZ process from being intercepted by address replacement !!)
23/01/2009 09:39:10 Function kernel32.dll:LoadLibraryExW (488) intercepted, method ProcAddressHijack.GetProcAddress ->77E90595->61F03E5A
23/01/2009 09:39:10 Hook kernel32.dll:LoadLibraryExW (488) blocked
23/01/2009 09:39:10 Function kernel32.dll:LoadLibraryW (489) intercepted, method ProcAddressHijack.GetProcAddress ->77E9031E->61F03D0C
23/01/2009 09:39:10 Hook kernel32.dll:LoadLibraryW (489) blocked
23/01/2009 09:39:10 IAT modification detected: LoadLibraryW - 00AE0010<>77E9031E
23/01/2009 09:39:10 Analysis: ntdll.dll, export table found in section .text
23/01/2009 09:39:10 Function ntdll.dll:NtCreateFile (92) intercepted, method CodeHijack (method not defined)
23/01/2009 09:39:10 >>> Rootkit code in function NtCreateFile blocked
23/01/2009 09:39:10 Function ntdll.dll:NtCreateProcess (101) intercepted, method CodeHijack (method not defined)
23/01/2009 09:39:10 >>> Rootkit code in function NtCreateProcess blocked
23/01/2009 09:39:10 Function ntdll.dll:NtOpenFile (163) intercepted, method CodeHijack (method not defined)
23/01/2009 09:39:10 >>> Rootkit code in function NtOpenFile blocked
23/01/2009 09:39:10 Analysis: user32.dll, export table found in section .text
23/01/2009 09:39:10 Analysis: advapi32.dll, export table found in section .text
23/01/2009 09:39:10 Analysis: ws2_32.dll, export table found in section .text
23/01/2009 09:39:10 Analysis: wininet.dll, export table found in section .text
23/01/2009 09:39:11 Analysis: rasapi32.dll, export table found in section .text
23/01/2009 09:39:11 Analysis: urlmon.dll, export table found in section .text
23/01/2009 09:39:11 Analysis: netapi32.dll, export table found in section .text
23/01/2009 09:39:11 1.2 Searching for kernel-mode API hooks
23/01/2009 09:39:12 Driver loaded successfully
23/01/2009 09:39:12 SDT found (RVA=0808E0)
23/01/2009 09:39:12 Kernel ntoskrnl.exe found in memory at address 80400000
23/01/2009 09:39:12 SDT = 804808E0
23/01/2009 09:39:12 KiST = 804721E8 (248)
23/01/2009 09:39:13 Function NtOpenProcess (6A) intercepted (804DEB24->EBA218AC), hook C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys, driver recognized as trusted
23/01/2009 09:39:13 >>> Function restored successfully !
23/01/2009 09:39:13 >>> Hook code blocked
23/01/2009 09:39:13 Function NtTerminateProcess (E0) intercepted (804E32CC->EBA21812), hook C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys, driver recognized as trusted
23/01/2009 09:39:13 >>> Function restored successfully !
23/01/2009 09:39:13 >>> Hook code blocked
23/01/2009 09:39:16 Functions checked: 248, intercepted: 2, restored: 2
23/01/2009 09:39:16 1.3 Checking IDT and SYSENTER
23/01/2009 09:39:16 Analysis for CPU 1
23/01/2009 09:39:16 Checking IDT and SYSENTER - complete
23/01/2009 09:39:17 >>>> Process masking detected 7044 ?
23/01/2009 09:39:17 >>>> Process masking detected 57008 ?
23/01/2009 09:39:17 >>>> Process masking detected 8400 ?
23/01/2009 09:39:17 >>>> Process masking detected 38868 ?
23/01/2009 09:39:17 >>>> Process masking detected 11708 ?
23/01/2009 09:39:17 1.4 Searching for masking processes and drivers
23/01/2009 09:39:17 Checking not performed: extended monitoring driver (AVZPM) is not installed
23/01/2009 09:39:17 Driver loaded successfully
23/01/2009 09:39:17 1.5 Checking of IRP handlers
23/01/2009 09:39:17 Checking - complete
23/01/2009 09:39:38 >>> C:\WINNT\services.exe HSC: suspicion for File with suspicious name (high degree of probability)
23/01/2009 09:39:39 >> Services: potentially dangerous service allowed: Alerter (Avertissement)
23/01/2009 09:39:39 >> Services: potentially dangerous service allowed: Schedule (Planificateur de tâches)
23/01/2009 09:39:39 >> Services: potentially dangerous service allowed: mnmsrvc (Partage de Bureau à distance NetMeeting)
23/01/2009 09:39:39 > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
23/01/2009 09:39:39 >> Security: disk drives' autorun is enabled
23/01/2009 09:39:39 >> Security: administrative shares (C$, D$ ...) are enabled
23/01/2009 09:39:39 >> Security: anonymous user access is enabled
23/01/2009 09:39:39 >> Security: terminal connections to the PC are allowed
23/01/2009 09:39:39 >> Security: sending Remote Assistant queries is enabled
23/01/2009 09:39:39 >> Security: automatic logon is enabled
23/01/2009 09:39:45 >> Service termination timeout is out of admissible values
23/01/2009 09:39:46 >> Disable HDD autorun
23/01/2009 09:39:46 >> Disable autorun from network drives
23/01/2009 09:39:46 >> Disable CD/DVD autorun
23/01/2009 09:39:46 >> Disable removable media autorun
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Bonjour,

.

Dans le répertoire Kaspersky Lab Tool qui est sur le bureau tu cherches "" unins000.exe"" et tu double clic dessus pour le desinstaller completement.

Via le Panneau de configuration, tu désinstalles toutes les applications non essentielles.

Démarrer, exécuter, tape combofix /u dans la zone de saisie et OK.

Supprime tous les fix .

Vide ta corbeille.

Désactive la restauration système.

Si tu as la possibilité, télécharge les outils sur un PC sain et grave sur sur un CD réinscriptible les fichiers téléchargés.

Tu commences avec Combofix, Antivir et Kaspersky AVP Tool

=============================
Tu introduis le CD. Si ce n'est pas possible, tu télécharges les 3 et tu les enregistres sous le nom XXXX.exe.ren

Tu les renommeras XXXX.exe juste avant de t'en servir.

Tu redémarres en mode sans échec (avec prise en charge réseau si c'est possible sous 2000).

Tu copies combofix sur le Bureau (i=ou tu renommes combofix.exe.ren en combofix.exe).

Démarrer, exécuter, tu tapes
combofix /killal
puis OK.

Si possible, tu redémarres directement en mode sans échec.

============================

Tu copies Kaspersky AVP Tool et tu l'exécutes avec la procédure que je t'ai donné.

Si il a désinfecté, tu essayes d'installer antivir.

Tu postes le rapport AVP tool.

=============================

Courage.
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
- comment fait-on pour désactiver la restauration systeme?

- est ce considéré comme non essentiel : sdfix, haxfix, ccleaner, HJT, AVG antispy, toolbarSD...

- je tente ce we de faire le cd sur paris (pas réinscriptible c'est pas grave? tant pis popur le cd, je le garderai en souvenir de notre épopée)

- prise en charge avec réseau, c'est aussi possible sous windows 2000

Bon ben je vais devoir partir, donc, je te souhaite un bon we avec des virus un peu plus gentils ;-)

Je pars dans une heure, donc j'attends ta réponse.

Est ce que la partition D est touchée?,et le disque dur que je branche de temps en temps (certainement nommé E) est il touché lui aussi, car si ce n'est pas le cas je peux virer d'autres trucs de C que j'ai mis sur E, sinon je ne touche pas à mes "trucs" perso plutot importants

Merci pour tout lyonnais92,

Karine
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Re,

restauration :

la procédure sous ME : version Symantec

http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830091903924

la procédure sous Xp : version Symantec
version Symantec

http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924

essentiel : dans ta liste, garde AVG antispy et CCleaner (tu peux le supprimer mais tu l'ajoutes dans la liste à graver)

gravage : OK pour non réinscriptible, garde l'option permetant d'ajouter à la fin.

ajoute à la liste HJT, SDFix

OAD : http://sosvirus.changelog.fr/OAD.exe

OTMoveIt3 : http://oldtimer.geekstogo.com/OTMoveIt3.exe

zebrestore : http://telechargement.zebulon.fr/zeb-restore.html


Ne peuvent être touchés que des .exe. Je ne sais pas si tes autres partitions sont indemnes. Je me suis fié à ce que tu as dit que AVP Tool n'y avait rien décelé d'infecté.


Je suis là très régulièrement mais, pour info, ta prochaine apparition c'est ?
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
bon malgré les liens je ne trouve pas le lieu ou désactiver la restauration du systeme, et je dois partir :-( je chercherai en rentrant

Alors pour etre sure :
je mets sur mon cd non réinscriptible :
- combofix,
- antivir
- kaspersky avptool
- HJT
- SDFix
- OAD
- OTMoveit3
- zebrestore

je rentre dimanche soir assez tard, alors je me reconnecte soit dimanche, soit lundi matin, en espérant que le virus n'aura pas fait trop de dégats

Merci encore lyonnias et à bientot
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Re,

pour la restauration système, ne cherche pas :

http://www.laboratoire-microsoft.org/articles/win/ad_sauve/

il n'y a pas d'équivalent.

Désolé de ne pas avoir vérifié avant.
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
bonjour lyonnais,de passage chez ma mère je t'informe que j'ai enregistré sur cd :

- zeb-restore
- combofix
- oad (ils disent que c'est un virus???!!!)
-rmvirut
- avg tool
- antivir,
- HJT
- otmoveit3
- sdfix
- vundofix

je vais ajouter ccleaner et malwarebytes au passage pour avoir des logiciels tout propre...

Vois tu autre chose à rajouter pendant que j'ai un ordi sain sous la main.

Je ne rentre pas avant 23h chez moi ce soir , alors si jamais donne moi des instructions pour entamer d'éventuels scans ce soir, qui seront dispo demain.Je te souhaite une bonne fin de we :-)

A PROPOS , ON M'A CONSEILLé D'INSTALLER LA VERSION GRATuiTE D'UN MOIS DE KASPERSKY QUI PERMETTRAIT DE NETTOYER PAS MAL DE CHOSES DE L'ORDI? DURANT UN MOIS ET DE REPRENDRE UN ANTIVIRUS GRATUIT ENSUITE... Tu en penses quoi?
0
Lyonnais92 Messages postés 25159 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 537
 
Bonjour,

je pense que c'est un bon cocktail.

Les AV considèrent comme "virus" des "risktools". Ce sont des outils "dangereux" mais nécessaires aux désinfections.

C'est une des raisons qui font qu'il faut nettoyer les outils à la fin.

A ton retour, tu peux lancer le post 170 (désinstallation de kasp AVP tool puis réinstallation et exécution).

L'ordi était éteint en ton absence ?

Répertoire :: C:\Program Files est un répertoire. C:\Program Files\Support Tools aussi (on dit aussi sous-répertoire).
0
lachoukrate Messages postés 234 Date d'inscription   Statut Membre Dernière intervention   2
 
oui l'ordi est eteind, donc normalement le virus n'a pas pu agir durant le we(enfin j'espère)
Ok pour le post 170, je m'étais arrétée à "la restauration du systeme". je vais aller voir ton lien à ce sujet...
Merci


euh si j'ai bien compris, il n'a pas de désactivation de restaration du systeme???
J'attaque directement la partie installer combofix?
0