Ordi infecte souri tremblote

saramine1 Messages postés 227 Statut Membre -  
Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour, a tous
je viens solliciter votre aide car je pense que je suis l'heureux proprietaire d'un ordi infecté
voila je suis sous xp pro sp3
ma souris optique s'est mise a vibrer en etant imprecise et c'est en faisant une recherchesur le net que j'ai pensé à une infection un controle sous bitdefender en ligne m'a trouvé des fichiers infectes
voici le rapport:

BitDefender Online Scanner

Rapport d'analyse généré à: Mon, Jul 06, 2009 - 23:07:04

Voie d'analyse: A:\;C:\;D:\;E:\;F:\;G:\;H:\;I:\;

Statistiques

Temps
01:12:32

Fichiers
70821

Directoires
5548

Secteurs de boot
0

Archives
1074

Paquets programmes
5689

Résultats

Virus identifiés
2

Fichiers infectés
3

Fichiers suspects
0

Avertissements
0

Désinfectés
0

Fichiers effacés
3

Info sur les moteurs

Définition virus
3434869

Version des moteurs
AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Analyse des plugins
15

Archive des plugins
42

Unpack des plugins
7

E-mail plugins
6

Système plugins
0

Paramètres d'analyse

Première action
Désinfecté

Seconde Action
Supprimé

Heuristique
Oui

Acceptez les avertissements
Oui

Extensions analysées
exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

Excludez les extensions

Analyse d'emails
Oui

Analyse des Archives
Oui

Analyser paquets programmes
Oui

Analyse des fichiers
Oui

Analyse de boot
Oui

Fichier analysé
Statut

D:\Documents and Settings\chebouti\Mes documents\Downloads\ImTOO AVI MPEG Converter v5.1 (NEW)\Setup.exe=>(ZIP Sfx o)=>11.6123.exe
Infecté par: Trojan.Downloader.Agent.ZPM

D:\Documents and Settings\chebouti\Mes documents\Downloads\ImTOO AVI MPEG Converter v5.1 (NEW)\Setup.exe=>(ZIP Sfx o)=>11.6123.exe
Echec de la désinfection

D:\Documents and Settings\chebouti\Mes documents\Downloads\ImTOO AVI MPEG Converter v5.1 (NEW)\Setup.exe=>(ZIP Sfx o)=>11.6123.exe
Supprimé

D:\Documents and Settings\chebouti\Mes documents\Downloads\ImTOO AVI MPEG Converter v5.1 (NEW)\Setup.exe=>(ZIP Sfx o)
Mis à jour

D:\Documents and Settings\chebouti\Mes documents\Downloads\ImTOO AVI MPEG Converter v5.1 (NEW)\Setup.exe
Echec de la mise à jour

D:\Kyle XY 01\GameSetup.exe
Infecté par: Packer.Malware.VPacker.B

D:\Kyle XY 01\GameSetup.exe
Echec de la désinfection

D:\Kyle XY 01\GameSetup.exe
Supprimé

D:\System Volume Information\_restore{E4695FE8-15D7-4FA4-ADC4-1DA44A7337B7}\RP698\A0256895.exe
Infecté par: Packer.Malware.VPacker.B

D:\System Volume Information\_restore{E4695FE8-15D7-4FA4-ADC4-1DA44A7337B7}\RP698\A0256895.exe
Echec de la désinfection

D:\System Volume Information\_restore{E4695FE8-15D7-4FA4-ADC4-1DA44A7337B7}\RP698\A0256895.exe
Supprimé

ensuite j'ai installé a-squaredqui m'a trouve des trojans
mais je crois que je ne saurai pas faire le nettoyage seul

c pour ca que je vous demande de me vvenir en aide

cordialement
Configuration: P3 Windows XP Internet Explorer 7.0

44 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Infection détectée sur un PC Windows XP Professionnel SP3 après des analyses en ligne qui mettent en évidence des fichiers infectés et des programmes malveillants tels que Trojan.Downloader.Agent.ZPM et Packer.Malware.VPacker.B. Des outils antivirus en ligne et des suites comme BitDefender Online Scanner et Kaspersky Online Scanner sont proposés pour désinfecter et supprimer les fichiers infectés, y compris ceux situés dans la restauration système. Des éléments signalent des échecs de désinfection et des suppressions manuelles, accompagnés de rapports détaillant des fichiers suspects et des entrées de registre à surveiller. En cas de doute, la prudence conseille de réaliser une analyse hors ligne et de vérifier les zones critiques comme les volumes D: et les données des restaurations système.

Bobot (l'IA à votre service)
  1. jeroscorpion Messages postés 928 Statut Contributeur 83
     
    tu as esséyer un autre anti virus?
    ou peut etre que ta souris a attraper la grippe porcine! ;)
    0
  2. saramine1 Messages postés 227 Statut Membre 6
     
    oui sacre gripe A
    mais c pas tellement la souris qui me preoccupe maintenant que les virus sachant que j'ai avast et zonalarm
    bon la souri est tombé donc je pense que ca viendrait aussi de son laser
    mais comment faire du nettoyage a fond
    merci
    0
  3. jeroscorpion Messages postés 928 Statut Contributeur 83
     
    il faut savoir que deux anti virus peuvent interférer,
    ensuite personnellement je déconseille avast essai avir il te dira surement que tu as deux virus et de les supprimer,
    quand a zone alarme vaguemen entendu parler!
    0
  4. saramine1 Messages postés 227 Statut Membre 6
     
    c vraie que avast est tres leger et pas gourmand en ressorce mais rien ne m'accroche a lui
    je le changerai bien plus tard mais je pense que j'ai eu une cette infection a l'installation de ImTOO AVI MPEG Converter . et que recemment, est ce que un nettoyage ne marcherait pas hijakthis serait utile ?
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jeroscorpion Messages postés 928 Statut Contributeur 83
     
    il te faut supprimer ton converter peu etre il mais just la panique avec ton anti virus!
    0
  7. saramine1 Messages postés 227 Statut Membre 6
     
    merci de ton aide
    mais d'a^res le rapport de bitdefender 3 fichiers sont infecté ne faut il pas desinfecté ou le simple fait d'enlever les ficheiers infecté suffit a desinfecté
    0
  8. jeroscorpion Messages postés 928 Statut Contributeur 83
     
    si tu sais quel fichier est infecté, tu peux le supprimer mais je ne sais pas si ça y fait, en tout cas vérifie que ton application converter fonctionne toujours avant de supprimer ton fichier définitivement!
    0
  9. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
     
    Tu as acheté ce logiciel de conversion?

    Si non, tu devrais le désinstaller et éventuellement lui préférer un de ceux-là.

    Afin de faire un diagnostic:

    - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

    - Double-clique sur RSIT.exe afin de lancer le programme.

    - Clique sur Continue à l'écran Disclaimer.

    -Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches) dans deux messages différents.
    0
  10. saramine1 Messages postés 227 Statut Membre 6
     
    non je n'ai pas acheter ce logiciel
    voici le rapport

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by chebouti at 2009-07-08 10:00:33
    Microsoft Windows XP Professionnel Service Pack 3
    System drive D: has 1 GB (7%) free of 15 GB
    Total RAM: 1007 MB (43% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:01:08, on 08/07/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16850)
    Boot mode: Normal

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\csrss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    D:\Program Files\Alwil Software\Avast4\ashServ.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\a-squared Anti-Malware\a2service.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\WINDOWS\System32\alg.exe
    D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    D:\Program Files\Java\jre6\bin\jusched.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Salaat Time\SalaatTime.exe
    D:\Program Files\Skype\Phone\Skype.exe
    D:\Program Files\DNA\btdna.exe
    D:\WINDOWS\system32\wbem\wmiapsrv.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\Skype\Plugin Manager\SkypePM.exe
    E:\download\a2AntiMalwareSetup.exe\RSIT.exe
    D:\WINDOWS\system32\wbem\wmiprvse.exe
    E:\download\antivirus\hijackthis\chebouti.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - D:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [a-squared] "D:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe" /d=60
    O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SalaatTime] D:\Program Files\Salaat Time\SalaatTime.exe
    O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [BitTorrent DNA] "D:\Program Files\DNA\btdna.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_6.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game05.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0E90D6DB-B6B7-4C8D-B60E-1CFC2EBC4DD5}: NameServer = 192.168.0.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0E90D6DB-B6B7-4C8D-B60E-1CFC2EBC4DD5}: NameServer = 192.168.0.1
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - D:\Program Files\a-squared Anti-Malware\a2service.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Il me faudrait aussi le "info.txt", stp.
      Il est situé dans C/:Rsit
      0
  11. saramine1 Messages postés 227 Statut Membre 6
     
    le voici

    info.txt logfile of random's system information tool 1.06 2009-07-08 10:02:09

    ======Uninstall list======

    -->D:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player 10 ActiveX-->D:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8.1.4 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
    Adobe Shockwave Player 11.5-->"D:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
    AIDA32 v3.93-->"D:\Program Files\AIDA32 - Enterprise System Information\unins000.exe"
    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    Archiveur WinRAR-->D:\Program Files\WinRAR\uninstall.exe
    a-squared Anti-Malware 4.5-->"D:\Program Files\a-squared Anti-Malware\unins000.exe"
    Atout Clic Anglais-->"C:\ATOUT CLIC ANGLAIS\Kids_CD2\bin\unsetup.exe" -file "C:\ATOUT CLIC ANGLAIS\Kids_CD2\bin\unsetup.aui"
    avast! Antivirus-->D:\Program Files\Alwil Software\Avast4\aswRunDll.exe "D:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
    AVIConverter 5.1.6-->D:\Program Files\AVIConverter\uninst.exe
    CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
    CDex extraction audio-->"D:\Program Files\CDex_150\uninstall.exe"
    Champions en s'amusant-->D:\Program Files\ATLAS\Champions\SYSTEM\AUTORUN_.EXE /UNINSTAL
    Correctif pour Lecteur Windows Media 11 (KB939683)-->"D:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
    Correctif pour Windows Internet Explorer 7 (KB947864)-->"D:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB952287)-->"D:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    DivX Codec-->D:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
    DivX Content Uploader-->D:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
    DivX Converter-->D:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
    DivX Player-->D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
    DivX Web Player-->D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    eMule2-->"D:\Program Files\eMule\uninstall.exe"
    FileZilla Client 3.2.6-->D:\Program Files\FileZilla FTP Client\uninstall.exe
    Freeplayer-->D:\Program Files\Freeplayer\Uninstall.exe
    Google Earth-->MsiExec.exe /I{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}
    HijackThis 2.0.2-->"E:\download\antivirus\hijackthis\HijackThis.exe" /uninstall
    Hotfix for Windows Media Format 11 SDK (KB929399)-->"D:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    HP Driver Diagnostics-->MsiExec.exe /I{6314D540-E3C1-4F30-AEEB-4154C93375C3}
    HP Product Detection-->MsiExec.exe /I{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
    ImTOO AVI MPEG Converter-->D:\Program Files\ImTOO\AVI MPEG Converter\Uninstall.exe
    J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
    Java(TM) 6 Update 14-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
    K-Lite Codec Pack 2.81 Full-->"D:\Program Files\K-Lite Codec Pack\unins000.exe"
    Lecteur Windows Media 11-->"D:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    L'Internet ADSL de Cegetel-->RunDll32 D:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{771A78EF-5482-480E-A6CB-04A12F268DAC}\Setup.exe" -l0x40c
    Logiciel QuickCam de Logitech-->RunDll32 D:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
    Maqplus 2003-->D:\WINDOWS\unin040c.exe -f"D:\Program Files\Jeulin\Maqplus 2003\DeIsL1.isu" -c"D:\Program Files\Jeulin\Maqplus 2003\_ISREG32.DLL"
    Mega Manager-->D:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe -runfromtemp -l0x0009 -removeonly
    Microsoft Compression Client Pack 1.0 for Windows XP-->"D:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Internationalized Domain Names Mitigation APIs-->"D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
    Microsoft User-Mode Driver Framework Feature Pack 1.0-->"D:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"D:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"D:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"D:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"D:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"D:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"D:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"D:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"D:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"D:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"D:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"D:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"D:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"D:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"D:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"D:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"D:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"D:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"D:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"D:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"D:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"D:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923561)-->"D:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB938464)-->"D:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB941569)-->"D:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"D:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950760)-->"D:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"D:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"D:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"D:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376)-->"D:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"D:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951698)-->"D:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"D:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952004)-->"D:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"D:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB953839)-->"D:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954211)-->"D:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954459)-->"D:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954600)-->"D:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"D:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956391)-->"D:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956572)-->"D:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956802)-->"D:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"D:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956841)-->"D:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957095)-->"D:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957097)-->"D:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958644)-->"D:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958687)-->"D:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958690)-->"D:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB959426)-->"D:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960225)-->"D:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960715)-->"D:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960803)-->"D:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB961373)-->"D:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB961501)-->"D:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB968537)-->"D:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB969898)-->"D:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB970238)-->"D:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951072-v2)-->"D:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951978)-->"D:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB955839)-->"D:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB967715)-->"D:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
    MSN-->D:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
    Norton PartitionMagic 8.0-->D:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{21DBBDD6-93A5-4326-9A04-C9A5C9148502}
    OTOY-->RunDll32 D:\WINDOWS\DOWNLO~1\OTOYAX.dll,_RemoveGroove@16
    PhotoFiltre-->"D:\Program Files\PhotoFiltre\Uninst.exe"
    Pro100-->D:\PROGRA~1\PRO100~1\UNWISE.EXE D:\PROGRA~1\PRO100~1\Pro100demo.LOG
    Programme de gestion Camera de Logitech®-->"D:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
    QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
    Radio Fr Solo 2.1-->D:\Program Files\Radio Fr Solo\Uninstall.exe
    Salaat Time 1.9-->D:\PROGRA~1\SALAAT~1\Setup.exe /remove /q0
    Salaat Time 2.0-->D:\PROGRA~1\SALAAT~1\Setup.exe /remove /q0
    Satsuki Decoder Pack-->D:\Program Files\Satsuki Decoder Pack\Uninstall.exe
    Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
    Spybot - Search & Destroy 1.5.2.20-->"D:\WINDOWS\unins000.exe"
    Spybot - Search & Destroy-->"D:\Program Files\Spybot - Search & Destroy\unins001.exe"
    Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
    Visual C++ 2008 x86 Runtime - v9.0.30729.01-->D:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
    VLC media player 0.9.9-->D:\Program Files\VideoLAN\VLC\uninstall.exe
    Windows Media Format 11 runtime-->"D:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Format 11 runtime-->"D:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    Windows Media Player 11-->"D:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
    Windows XP Service Pack 3-->"D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    ZoneAlarm-->D:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

    ======Security center information======

    AV: avast! antivirus 4.8.1335 [VPS 090707-0]
    AV: a-squared Anti-Malware (disabled) (outdated)
    FW: ZoneAlarm Firewall

    ======System event log======

    Computer Name: CHEBOUTI-9184BB
    Event Code: 7036
    Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

    Record Number: 511
    Source Name: Service Control Manager
    Time Written: 20090520133855.000000+120
    Event Type: Informations
    User:

    Computer Name: CHEBOUTI-9184BB
    Event Code: 7035
    Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

    Record Number: 510
    Source Name: Service Control Manager
    Time Written: 20090520133852.000000+120
    Event Type: Informations
    User: AUTORITE NT\SYSTEM

    Computer Name: CHEBOUTI-9184BB
    Event Code: 7036
    Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

    Record Number: 509
    Source Name: Service Control Manager
    Time Written: 20090520133852.000000+120
    Event Type: Informations
    User:

    Computer Name: CHEBOUTI-9184BB
    Event Code: 7036
    Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

    Record Number: 508
    Source Name: Service Control Manager
    Time Written: 20090520133852.000000+120
    Event Type: Informations
    User:

    Computer Name: CHEBOUTI-9184BB
    Event Code: 7035
    Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

    Record Number: 507
    Source Name: Service Control Manager
    Time Written: 20090520133852.000000+120
    Event Type: Informations
    User: AUTORITE NT\SYSTEM

    =====Application event log=====

    Computer Name: CHEBOUTI-9184BB
    Event Code: 1517
    Message: Windows a sauvegardé le Registre utilisateur CHEBOUTI-9184BB\chebouti alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

    Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

    Record Number: 363
    Source Name: Userenv
    Time Written: 20070603092935.000000+120
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: CHEBOUTI-9184BB
    Event Code: 1800
    Message: Le service Centre de sécurité Windows a démarré.

    Record Number: 362
    Source Name: SecurityCenter
    Time Written: 20070603091832.000000+120
    Event Type: Informations
    User:

    Computer Name: CHEBOUTI-9184BB
    Event Code: 1517
    Message: Windows a sauvegardé le Registre utilisateur CHEBOUTI-9184BB\chebouti alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

    Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

    Record Number: 361
    Source Name: Userenv
    Time Written: 20070603001942.000000+120
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: CHEBOUTI-9184BB
    Event Code: 7
    Message: Récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie réussie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

    Record Number: 360
    Source Name: crypt32
    Time Written: 20070602104430.000000+120
    Event Type: Informations
    User:

    Computer Name: CHEBOUTI-9184BB
    Event Code: 1800
    Message: Le service Centre de sécurité Windows a démarré.

    Record Number: 359
    Source Name: SecurityCenter
    Time Written: 20070602093651.000000+120
    Event Type: Informations
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;"D:\Program Files\Zone Labs\ZoneAlarm\MailFrontier";D:\Program Files\QuickTime\QTSystem\
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=6
    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 7 Stepping 1, AuthenticAMD
    "PROCESSOR_REVISION"=0701
    "NUMBER_OF_PROCESSORS"=1
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "tvdumpflags"=8
    "CLASSPATH"=.;D:\Program Files\Java\jre6\lib\ext\QTJava.zip
    "QTJAVA"=D:\Program Files\Java\jre6\lib\ext\QTJava.zip

    -----------------EOF-----------------
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Désolé, tu me l'avais bien posté, j'avais mal vu...

      Tu as une infection "USB", celle ci précisément.

      Il va donc falloir que tu branches ta ou tes clé(s) USB/Disque dur externe pour cette étape:


      • Télécharge et installe FindyKill

      (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir.

      • Double clic sur le raccourci FindyKill présent sur ton bureau .

      • Choisis l'option 1 ( Recherche )

      • Laisse travailler l'outil.

      • Ensuite poste le rapport FindyKill.txt qui apparaitra.

      • Note : Le rapport FindyKill.txt est sauvegardé a la racine du disque. ( C:\FindyKill.txt )


      • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
      0
  12. saramine1 Messages postés 227 Statut Membre 6
     
    ah ok ces derniers temp mes enfants preparer leur vacance en faisant le plein dans leur mp3 (qui je pense doivent etre tester aussi)
    je vais faire ce que tu m'as dit de suite
    merci
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Tu as raison, il faut brancher tous les MP3.

      Ce genre d'infection se propage justement par ce biais.
      De plus tu as de la "chance", le logiciel que nous allons utiliser "vaccinera" tes clés et les rendra insensible à ce genre d'infection.
      0
  13. saramine1 Messages postés 227 Statut Membre 6
     
    voici le rapport mais je n'ai mis les autres cles et mp3
    je suppose qu'il faut relancer a chaque le logiciel pour verifier mais est ce qu'il va pour chaque verifier tous les dd internes

    sinon voila le rapport ou le 1er

    ############################## | FindyKill V6.003 |

    # User : chebouti (Administrateurs) # CHEBOUTI-9184BB
    # Update on 07/07/09 by Chiquitine29 & C_XX
    # Start at: 11:31:32 | 08/07/2009
    # Website : http://pagesperso-orange.fr/NosTools/index.html

    # AMD Duron(tm) Processor
    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    # Internet Explorer 7.0.5730.11
    # Windows Firewall Status : Disabled
    # AV : avast! antivirus 4.8.1335 [VPS 090707-0] 4.8.1335 [ Enabled | Updated ]
    # AV : a-squared Anti-Malware 4 [ (!) Disabled | (!) Outdated ]
    # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

    # A:\ # Lecteur de disquettes 3 ½ pouces
    # C:\ # Disque fixe local # 39,08 Go (2,69 Go free) [RIME] # NTFS
    # D:\ # Disque fixe local # 14,93 Go (966,02 Mo free) [SARAH] # NTFS
    # E:\ # Disque fixe local # 20,5 Go (4,34 Go free) [AMINE] # FAT32
    # F:\ # Disque fixe local # 76,69 Go (2,55 Go free) [ALGERIE] # NTFS
    # G:\ # Disque CD-ROM
    # H:\ # Disque amovible # 959,88 Mo (166,5 Mo free) [PHILIPS] # FAT32

    ############################## | Processus actifs |

    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\csrss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    D:\Program Files\Alwil Software\Avast4\ashServ.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\a-squared Anti-Malware\a2service.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\WINDOWS\System32\alg.exe
    D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    D:\Program Files\Java\jre6\bin\jusched.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Salaat Time\SalaatTime.exe
    D:\Program Files\Skype\Phone\Skype.exe
    D:\Program Files\DNA\btdna.exe
    D:\WINDOWS\system32\wbem\wmiapsrv.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\Skype\Plugin Manager\SkypePM.exe
    D:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Registre Startup |

    HKCU_Main: "Local Page"="D:\\WINDOWS\\system32\\blank.htm"
    HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
    HKCU_Main: "Start Page"="https://fr.yahoo.com/"
    HKLM_logon: "Userinit"="D:\\WINDOWS\\system32\\userinit.exe,"
    HKLM_logon: "DefaultUserName"="chebouti"
    HKLM_logon: "AltDefaultUserName"="chebouti"
    HKLM_logon: "LegalNoticeCaption"=""
    HKLM_logon: "LegalNoticeText"=""
    HKLM_Run: avast!=D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    HKLM_Run: ZoneAlarm Client="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    HKLM_Run: QuickTime Task="D:\Program Files\QuickTime\qttask.exe" -atboottime
    HKLM_Run: SunJavaUpdateSched="D:\Program Files\Java\jre6\bin\jusched.exe"
    HKLM_Run: a-squared="D:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe" /d=60
    HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    HKCU_Run: CTFMON.EXE=D:\WINDOWS\system32\ctfmon.exe
    HKCU_Run: SalaatTime=D:\Program Files\Salaat Time\SalaatTime.exe
    HKCU_Run: Skype="D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    HKCU_Run: BitTorrent DNA="D:\Program Files\DNA\btdna.exe"

    ################## | Fichiers # Dossiers infectieux |

    Présent ! D:\WINDOWS\Prefetch\KEYGEN.EXE-28B881C9.pf

    ################## | D:\Documents and Settings\chebouti\Temporary Internet Files |

    Présent ! D:\Documents and Settings\chebouti\Cookies\chebouti@www.crackserialcodes[1].txt

    ################## | All Drives ... |

    Présent ! F:\autorun.inf

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    HKCU\...\Explorer\MountPoints2\{81b6ebe0-4a69-11dd-9aec-0090d0766a5a}\Shell\Auto\Command
    HKCU\...\Explorer\MountPoints2\{81b6ebe0-4a69-11dd-9aec-0090d0766a5a}\Shell\AutoRun\Command

    ################## | Etat / Services / Informations |

    # Affichage des fichiers cachés : OK

    # Mode sans echec : OK

    # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
    # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
    # Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
    # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
    # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
    # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

    ################## | Cracks / Keygens / Serials |

    ################## | ! Fin du rapport # FindyKill V6.003 ! |

    merci de ton aide
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectées sans les ouvrir

      • Double clic sur le raccourci FindyKill présent sur ton bureau

      • choisis l'option 2 ( Suppression )

      • Ton bureau disparaitra et le pc redémarrera .

      • Au redémarrage , FindyKill scannera ton pc , laisse travailler l'outil.

      • Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

      • Note : Le rapport FindyKill.txt est sauvegardé a la racine du disque.( C:\FindyKill.txt )
      0
  14. saramine1 Messages postés 227 Statut Membre 6
     
    une question stp pour scanner ttes les cles usb comment faire?
    thks.
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      C'est la Fnac chez toi?
      :)


      Fais l'étape 2 de findykill, avec les mêmes clés qui étaient branchées lors du 1er scan.

      Si tu en as d'autres on refera ensuite une nouvelle étape de recherche, en enlevant celles précédemment scannées et en branchant juste celles qui n'ont pas encore été connectées.
      0
  15. saramine1 Messages postés 227 Statut Membre 6
     
    Donc le rapport est la
    ############################## | FindyKill V6.003 |

    # User : chebouti (Administrateurs) # CHEBOUTI-9184BB
    # Update on 07/07/09 by Chiquitine29 & C_XX
    # Start at: 12:32:58 | 08/07/2009
    # Website : http://pagesperso-orange.fr/NosTools/index.html

    # AMD Duron(tm) Processor
    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    # Internet Explorer 7.0.5730.11
    # Windows Firewall Status : Disabled
    # AV : avast! antivirus 4.8.1335 [VPS 090707-0] 4.8.1335 [ Enabled | Updated ]
    # AV : a-squared Anti-Malware 4 [ (!) Disabled | (!) Outdated ]
    # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

    # A:\ # Lecteur de disquettes 3 ½ pouces
    # C:\ # Disque fixe local # 39,08 Go (2,69 Go free) [RIME] # NTFS
    # D:\ # Disque fixe local # 14,93 Go (942,89 Mo free) [SARAH] # NTFS
    # E:\ # Disque fixe local # 20,5 Go (4,34 Go free) [AMINE] # FAT32
    # F:\ # Disque fixe local # 76,69 Go (2,55 Go free) [ALGERIE] # NTFS
    # G:\ # Disque CD-ROM
    # H:\ # Disque amovible # 959,88 Mo (166,5 Mo free) [PHILIPS] # FAT32

    ############################## | Processus actifs |

    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\csrss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\WINDOWS\system32\WgaTray.exe
    D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Alwil Software\Avast4\ashServ.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\Alwil Software\Avast4\setup\avast.setup
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\a-squared Anti-Malware\a2service.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\WINDOWS\system32\wbem\wmiprvse.exe
    D:\WINDOWS\System32\alg.exe

    ################## | Fichiers # Dossiers infectieux |

    Supprimé ! D:\WINDOWS\Prefetch\KEYGEN.EXE-28B881C9.pf

    ################## | D:\Documents and Settings\chebouti\Temporary Internet Files |

    Supprimé ! D:\Documents and Settings\chebouti\Cookies\chebouti@www.crackserialcodes[1].txt

    ################## | All Drives ... |

    Supprimé ! F:\autorun.inf

    ################## | Autres ... |

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    Supprimé ! HKCU\...\Explorer\MountPoints2\{81b6ebe0-4a69-11dd-9aec-0090d0766a5a}\Shell\Auto\Command

    ################## | Listing des fichiers présent |

    [12/06/2009 08:15|--a------|39420] - C:\aaw7boot.log
    [19/07/2007 15:44|--a------|138] - C:\abdo255.ram
    [10/03/2007 11:23|--a------|0] - C:\AUTOEXEC.BAT
    [14/06/2009 00:24|---hs----|212] - C:\boot.ini
    [05/08/2004 14:00|-rahs----|4952] - C:\Bootfont.bin
    [10/03/2007 11:23|--a------|0] - C:\CONFIG.SYS
    [10/03/2007 11:23|-rahs----|0] - C:\IO.SYS
    [10/03/2007 11:23|-rahs----|0] - C:\MSDOS.SYS
    [05/08/2004 14:00|-rahs----|47564] - C:\NTDETECT.COM
    [30/04/2008 17:26|-rahs----|252240] - C:\ntldr
    [02/02/2009 00:23|--ahs----|1584635904] - C:\pagefile.sys
    [11/04/2009 11:50|--a------|0] - C:\Push.FRENCH.BDRiP.XviD-SURViVAL.avi
    [06/01/2008 02:06|--a------|12559904] - C:\SalaatTimeSetup.exe
    [29/03/2007 21:13|--ahs----|8192] - C:\Thumbs.db
    [08/07/2009 13:47|--a------|3471] - D:\FindyKill.txt
    [||] - D:\hiberfil.sys
    [29/08/2007 23:47|--a------|54600] - D:\npbittorrent.dll
    [||] - D:\pagefile.sys
    [18/01/2008 18:19|--a------|1563] - D:\RFScheduler.lnk
    [11/04/2009 11:50|--a------|0] - E:\LA.NUIT AU MUSEE.avi
    [11/04/2009 11:50|--a------|0] - F:\3.Pigs.And.A.Baby.STV.COMPLETE.NTSC.MULTi.DVDR.By.Kaam.iso
    [11/04/2009 11:50|--a------|0] - F:\LA.NUIT AU MUSEE.avi
    [02/04/2008 12:54|--a------|211557292] - F:\realisation2007-2.zip
    [05/03/2009 23:08|--a------|133200062] - F:\RǸalisationd'unobjettechnique.rar
    [13/04/2008 20:34|--a------|28672] - F:\setupSNK.exe
    [07/07/2000 09:00|---hs----|4194304] - H:\MUSIC.LIB
    [07/07/2000 00:00|---hs----|50176] - H:\MUSIC.SEC
    [27/12/2002 18:44|---hs----|135] - H:\PHOTO.LIB
    [27/12/2002 18:44|---hs----|270] - H:\MOVIE.LIB
    [27/12/2002 18:44|-rahs----|822] - H:\SETTINGS.DAT
    [05/07/2009 18:34|--a------|296] - H:\WMPInfo.xml

    ################## | Vaccination |

    # C:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # D:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # E:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # F:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # H:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.

    ################## | Etat / Services / Informations |

    # Mode sans echec : OK

    # Affichage des fichiers cachés : OK

    # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
    # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
    # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
    # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
    # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
    # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

    ################## | PEH ... |

    ################## | Cracks / Keygens / Serials |

    "D:\Documents and Settings\chebouti\.housecall6.6\patch.exe"
    06/07/2009 20:31 |Size : 218736 |Crc32 : 12c79c8b |Md5 : b9a80ba0083fb8196f8ca0bef053ea4e

    ################## | ! Fin du rapport # FindyKill V6.003 ! |
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Si tu as d'autres clés qui n'ont pas pu être analysées, branche les en prenant soit de déconnecter celles qui ont été déjà scannées.

      Poste moi le rapport de l'option 1 de Findykill.

      Si toutes tes clés USB ont déjà été analysées passe directement à cela:


      Télécharge Malwarebytes' Anti-Malware (MBAM)

      * Double clique sur le fichier téléchargé pour lancer le processus d'installation.
      * Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
      * Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
      * Sélectionne "Exécuter un examen rapide"
      * Clique sur "Rechercher"
      * L'analyse démarre, le scan est relativement long, c'est normal.
      * A la fin de l'analyse, un message s'affiche :

      "L'examen s'est terminé normalement. "

      Clique sur "Afficher les résultats" pour afficher tous les objets trouvés.

      Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.

      * Ferme tes navigateurs. (Internet Explorer/ Firefox...)
      * Si des malwares ont été détectés, clique sur Afficher les résultats.
      Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
      * MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.

      @+
      0
  16. saramine1 Messages postés 227 Statut Membre 6
     
    ok je scanne les autres cles de suite ensuite j'installe mbam
    a tt a l'heure
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      D'abord l'option 1 alors.

      Laisse tomber MBAM pour l'instant.
      0
  17. saramine1 Messages postés 227 Statut Membre 6
     
    le 2e rapport

    ############################## | FindyKill V6.003 |

    # User : chebouti (Administrateurs) # CHEBOUTI-9184BB
    # Update on 07/07/09 by Chiquitine29 & C_XX
    # Start at: 16:07:45 | 08/07/2009
    # Website : http://pagesperso-orange.fr/NosTools/index.html

    # AMD Duron(tm) Processor
    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    # Internet Explorer 7.0.5730.11
    # Windows Firewall Status : Disabled
    # AV : avast! antivirus 4.8.1335 [VPS 090707-0] 4.8.1335 [ Enabled | Updated ]
    # AV : a-squared Anti-Malware 4 [ (!) Disabled | (!) Outdated ]
    # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

    # A:\ # Lecteur de disquettes 3 ½ pouces
    # C:\ # Disque fixe local # 39,08 Go (2,69 Go free) [RIME] # NTFS
    # D:\ # Disque fixe local # 14,93 Go (994,81 Mo free) [SARAH] # NTFS
    # E:\ # Disque fixe local # 20,5 Go (4,33 Go free) [AMINE] # FAT32
    # F:\ # Disque fixe local # 76,69 Go (2,55 Go free) [ALGERIE] # NTFS
    # G:\ # Disque CD-ROM
    # H:\ # Disque amovible # 3,79 Go (2,76 Go free) [ARCHOS 2] # FAT32
    # I:\ # Disque amovible

    ############################## | Processus actifs |

    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\csrss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    D:\Program Files\Alwil Software\Avast4\ashServ.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\a-squared Anti-Malware\a2service.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\WINDOWS\System32\alg.exe
    D:\WINDOWS\system32\wbem\wmiapsrv.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\explorer.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Registre Startup |

    HKCU_Main: "Local Page"="D:\\WINDOWS\\system32\\blank.htm"
    HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
    HKCU_Main: "Start Page"="https://fr.yahoo.com/"
    HKLM_logon: "Userinit"="D:\\WINDOWS\\system32\\userinit.exe,"
    HKLM_logon: "DefaultUserName"="chebouti"
    HKLM_logon: "AltDefaultUserName"="chebouti"
    HKLM_logon: "LegalNoticeCaption"=""
    HKLM_logon: "LegalNoticeText"=""
    HKLM_Run: avast!=D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    HKLM_Run: ZoneAlarm Client="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    HKLM_Run: QuickTime Task="D:\Program Files\QuickTime\qttask.exe" -atboottime
    HKLM_Run: SunJavaUpdateSched="D:\Program Files\Java\jre6\bin\jusched.exe"
    HKLM_Run: a-squared="D:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe" /d=60
    HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    HKCU_Run: CTFMON.EXE=D:\WINDOWS\system32\ctfmon.exe
    HKCU_Run: SalaatTime=D:\Program Files\Salaat Time\SalaatTime.exe
    HKCU_Run: Skype="D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    HKCU_Run: BitTorrent DNA="D:\Program Files\DNA\btdna.exe"

    ################## | Fichiers # Dossiers infectieux |

    ################## | D:\Documents and Settings\chebouti\Temporary Internet Files |

    ################## | All Drives ... |

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    ################## | Etat / Services / Informations |

    # Affichage des fichiers cachés : OK

    # Mode sans echec : OK

    # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
    # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
    # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
    # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
    # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
    # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

    ################## | Cracks / Keygens / Serials |

    ################## | ! Fin du rapport # FindyKill V6.003 ! |
    0
  18. saramine1 Messages postés 227 Statut Membre 6
     
    voici le dernier rapport avec l'option 1
    cordialement
    0
  19. saramine1 Messages postés 227 Statut Membre 6
     
    oups j'ai oublié le rapport

    ############################## | FindyKill V6.003 |

    # User : chebouti (Administrateurs) # CHEBOUTI-9184BB
    # Update on 07/07/09 by Chiquitine29 & C_XX
    # Start at: 18:45:49 | 08/07/2009
    # Website : http://pagesperso-orange.fr/NosTools/index.html

    # AMD Duron(tm) Processor
    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    # Internet Explorer 7.0.5730.11
    # Windows Firewall Status : Disabled
    # AV : avast! antivirus 4.8.1335 [VPS 090707-0] 4.8.1335 [ Enabled | Updated ]
    # AV : a-squared Anti-Malware 4 [ (!) Disabled | (!) Outdated ]
    # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

    # A:\ # Lecteur de disquettes 3 ½ pouces
    # C:\ # Disque fixe local # 39,08 Go (2,69 Go free) [RIME] # NTFS
    # D:\ # Disque fixe local # 14,93 Go (965,76 Mo free) [SARAH] # NTFS
    # E:\ # Disque fixe local # 20,5 Go (4,33 Go free) [AMINE] # FAT32
    # F:\ # Disque fixe local # 76,69 Go (2,55 Go free) [ALGERIE] # NTFS
    # G:\ # Disque CD-ROM
    # H:\ # Disque amovible # 3,79 Go (1,75 Go free) [ARCHOS 2] # FAT32
    # I:\ # Disque amovible
    # J:\ # Disque amovible # 1,9 Go (826,95 Mo free) # FAT32

    ############################## | Processus actifs |

    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\csrss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    D:\Program Files\Alwil Software\Avast4\ashServ.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\a-squared Anti-Malware\a2service.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\WINDOWS\System32\alg.exe
    D:\WINDOWS\system32\wbem\wmiapsrv.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\explorer.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Registre Startup |

    HKCU_Main: "Local Page"="D:\\WINDOWS\\system32\\blank.htm"
    HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
    HKCU_Main: "Start Page"="https://fr.yahoo.com/"
    HKLM_logon: "Userinit"="D:\\WINDOWS\\system32\\userinit.exe,"
    HKLM_logon: "DefaultUserName"="chebouti"
    HKLM_logon: "AltDefaultUserName"="chebouti"
    HKLM_logon: "LegalNoticeCaption"=""
    HKLM_logon: "LegalNoticeText"=""
    HKLM_Run: avast!=D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    HKLM_Run: ZoneAlarm Client="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    HKLM_Run: QuickTime Task="D:\Program Files\QuickTime\qttask.exe" -atboottime
    HKLM_Run: SunJavaUpdateSched="D:\Program Files\Java\jre6\bin\jusched.exe"
    HKLM_Run: a-squared="D:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe" /d=60
    HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    HKCU_Run: CTFMON.EXE=D:\WINDOWS\system32\ctfmon.exe
    HKCU_Run: SalaatTime=D:\Program Files\Salaat Time\SalaatTime.exe
    HKCU_Run: Skype="D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    HKCU_Run: BitTorrent DNA="D:\Program Files\DNA\btdna.exe"

    ################## | Fichiers # Dossiers infectieux |

    ################## | D:\Documents and Settings\chebouti\Temporary Internet Files |

    ################## | All Drives ... |

    Présent ! J:\autorun.inf

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    ################## | Etat / Services / Informations |

    # Affichage des fichiers cachés : OK

    # Mode sans echec : OK

    # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
    # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
    # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
    # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
    # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
    # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

    ################## | Cracks / Keygens / Serials |

    ################## | ! Fin du rapport # FindyKill V6.003 ! |
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Tu peux relancer l'option 2 avec les même périphériques branchés.
      0
  20. saramine1 Messages postés 227 Statut Membre 6
     
    ok thks
    0
  21. saramine1 Messages postés 227 Statut Membre 6
     
    enfin le rapport pour la 2e option

    ############################## | FindyKill V6.003 |

    # User : chebouti (Administrateurs) # CHEBOUTI-9184BB
    # Update on 07/07/09 by Chiquitine29 & C_XX
    # Start at: 19:19:24 | 08/07/2009
    # Website : http://pagesperso-orange.fr/NosTools/index.html

    # AMD Duron(tm) Processor
    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    # Internet Explorer 7.0.5730.11
    # Windows Firewall Status : Enabled
    # AV : avast! antivirus 4.8.1335 [VPS 090707-0] 4.8.1335 [ Enabled | Updated ]
    # AV : a-squared Anti-Malware 4 [ (!) Disabled | (!) Outdated ]
    # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

    # A:\ # Lecteur de disquettes 3 ½ pouces
    # C:\ # Disque fixe local # 39,08 Go (2,69 Go free) [RIME] # NTFS
    # D:\ # Disque fixe local # 14,93 Go (971,4 Mo free) [SARAH] # NTFS
    # E:\ # Disque fixe local # 20,5 Go (4,33 Go free) [AMINE] # FAT32
    # F:\ # Disque fixe local # 76,69 Go (2,55 Go free) [ALGERIE] # NTFS
    # G:\ # Disque CD-ROM
    # J:\ # Disque amovible # 1,9 Go (826,95 Mo free) # FAT32

    ############################## | Processus actifs |

    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\csrss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\system32\ZoneLabs\vsmon.exe
    D:\WINDOWS\system32\WgaTray.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    D:\Program Files\Alwil Software\Avast4\ashServ.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\Alwil Software\Avast4\setup\avast.setup
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\a-squared Anti-Malware\a2service.exe
    D:\WINDOWS\System32\svchost.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    D:\WINDOWS\system32\wbem\wmiprvse.exe
    D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    D:\WINDOWS\System32\alg.exe

    ################## | Fichiers # Dossiers infectieux |

    ################## | D:\Documents and Settings\chebouti\Temporary Internet Files |

    ################## | All Drives ... |

    Supprimé ! J:\autorun.inf

    ################## | Autres ... |

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    ################## | Listing des fichiers présent |

    [12/06/2009 08:15|--a------|39420] - C:\aaw7boot.log
    [19/07/2007 15:44|--a------|138] - C:\abdo255.ram
    [10/03/2007 11:23|--a------|0] - C:\AUTOEXEC.BAT
    [14/06/2009 00:24|---hs----|212] - C:\boot.ini
    [05/08/2004 14:00|-rahs----|4952] - C:\Bootfont.bin
    [10/03/2007 11:23|--a------|0] - C:\CONFIG.SYS
    [10/03/2007 11:23|-rahs----|0] - C:\IO.SYS
    [10/03/2007 11:23|-rahs----|0] - C:\MSDOS.SYS
    [05/08/2004 14:00|-rahs----|47564] - C:\NTDETECT.COM
    [30/04/2008 17:26|-rahs----|252240] - C:\ntldr
    [02/02/2009 00:23|--ahs----|1584635904] - C:\pagefile.sys
    [11/04/2009 11:50|--a------|0] - C:\Push.FRENCH.BDRiP.XviD-SURViVAL.avi
    [06/01/2008 02:06|--a------|12559904] - C:\SalaatTimeSetup.exe
    [29/03/2007 21:13|--ahs----|8192] - C:\Thumbs.db
    [08/07/2009 20:32|--a------|3236] - D:\FindyKill.txt
    [||] - D:\hiberfil.sys
    [29/08/2007 23:47|--a------|54600] - D:\npbittorrent.dll
    [||] - D:\pagefile.sys
    [18/01/2008 18:19|--a------|1563] - D:\RFScheduler.lnk
    [08/07/2009 13:47|--a------|4411] - D:\UsbFix.txt
    [11/04/2009 11:50|--a------|0] - E:\LA.NUIT AU MUSEE.avi
    [11/04/2009 11:50|--a------|0] - F:\3.Pigs.And.A.Baby.STV.COMPLETE.NTSC.MULTi.DVDR.By.Kaam.iso
    [11/04/2009 11:50|--a------|0] - F:\LA.NUIT AU MUSEE.avi
    [02/04/2008 12:54|--a------|211557292] - F:\realisation2007-2.zip
    [05/03/2009 23:08|--a------|133200062] - F:\RǸalisationd'unobjettechnique.rar
    [13/04/2008 20:34|--a------|28672] - F:\setupSNK.exe
    [08/03/2006 15:54|-ra------|1354650] - J:\del_clib_mala_nova_b.mp3
    [05/08/2008 18:13|-ra------|813] - J:\launch.bat
    [28/01/2005 10:45|-ra------|2068608] - J:\MiddleEasternDanceTrack.mp3
    [05/08/2008 18:17|-ra------|40861176] - J:\mpman-mpmanager.exe
    [10/02/2009 14:46|--ah-----|296] - J:\WMPInfo.xml
    [02/02/2009 19:56|--a------|87330660] - J:\Ben lkbir.wav

    ################## | Vaccination |

    # C:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # D:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # E:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # F:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
    # J:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.

    ################## | Etat / Services / Informations |

    # Mode sans echec : OK

    # Affichage des fichiers cachés : OK

    # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
    # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
    # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
    # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
    # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
    # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

    ################## | PEH ... |

    ################## | Cracks / Keygens / Serials |

    "D:\Documents and Settings\chebouti\.housecall6.6\patch.exe"
    06/07/2009 20:31 |Size : 218736 |Crc32 : 12c79c8b |Md5 : b9a80ba0083fb8196f8ca0bef053ea4e

    ################## | ! Fin du rapport # FindyKill V6.003 ! |
    0
  • 1
  • 2
  • 3