Virus empeche d'ouvrir HijackThis

Résolu
tobor -  
 Utilisateur anonyme -
Bonjour,
J'ai un probleme, quand j'ouvre internet explorer l'ordi gele et je suis obligé de faire un reset, j'ai réussi a installer firefox avec ma clef usb et je peut aller sur internet, c'est déja ça, sauf que les pages sont redirigé, j'ai réussi a installer Antivir et je vous donne le rapport. J'ai winxp sp3 pentium 4 2.8.
Merci de bien vouloir m'aider.

Avira AntiVir Personal
Report file date: 25 juillet 2009 14:15

Scanning for 1567743 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : Administrateur
Computer name : DELL

Version information:
BUILD.DAT : 9.0.0.403 17961 Bytes 2009-06-03 17:05:00
AVSCAN.EXE : 9.0.3.6 466689 Bytes 2009-05-11 08:14:47
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2009-02-27 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2009-02-20 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2009-02-27 09:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 2008-10-27 11:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 2009-06-24 11:57:15
ANTIVIR2.VDF : 7.1.4.253 1779200 Bytes 2009-07-19 11:57:29
ANTIVIR3.VDF : 7.1.5.28 214528 Bytes 2009-07-24 11:57:31
Engineversion : 8.2.0.228
AEVDF.DLL : 8.1.1.1 106868 Bytes 2009-04-30 10:52:04
AESCRIPT.DLL : 8.1.2.18 442746 Bytes 2009-07-25 11:57:46
AESCN.DLL : 8.1.2.4 127348 Bytes 2009-07-25 11:57:44
AERDL.DLL : 8.1.2.4 430452 Bytes 2009-07-25 11:57:44
AEPACK.DLL : 8.1.3.18 401783 Bytes 2009-05-27 15:07:20
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 2009-07-25 11:57:42
AEHEUR.DLL : 8.1.0.143 1864055 Bytes 2009-07-25 11:57:41
AEHELP.DLL : 8.1.5.3 233846 Bytes 2009-07-25 11:57:34
AEGEN.DLL : 8.1.1.50 352629 Bytes 2009-07-25 11:57:33
AEEMU.DLL : 8.1.0.9 393588 Bytes 2008-10-09 13:32:40
AECORE.DLL : 8.1.7.6 184694 Bytes 2009-07-25 11:57:32
AEBB.DLL : 8.1.0.3 53618 Bytes 2008-10-09 13:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 2008-12-12 07:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 2008-12-05 09:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 2009-01-20 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 2008-12-05 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 2009-03-24 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 2009-01-30 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 2009-01-28 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2009-02-02 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 2008-12-05 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 2009-05-15 14:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 2009-04-17 09:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: 25 juillet 2009 14:15

Starting search for hidden objects.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ESQULserv.sys\modules
[INFO] The registry entry is invisible.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ESQULserv.sys\start
[INFO] The registry entry is invisible.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ESQULserv.sys\type
[INFO] The registry entry is invisible.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ESQULserv.sys\imagepath
[INFO] The registry entry is invisible.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ESQULserv.sys\group
[INFO] The registry entry is invisible.
'7549' objects were checked, '5' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'avgcsrvx.exe' - '1' Module(s) have been scanned
Scan process 'nmsrvc.exe' - '1' Module(s) have been scanned
Scan process 'avgemc.exe' - '1' Module(s) have been scanned
Scan process 'avgnsx.exe' - '1' Module(s) have been scanned
Scan process 'avgrsx.exe' - '1' Module(s) have been scanned
Scan process 'avgam.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'avgwdsvc.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'nmapp.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'avgtray.exe' - '1' Module(s) have been scanned
Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'savedump.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
39 processes with 39 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '60' files ).

Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\Administrateur\Local Settings\Temp\5df3805d-e8d3-4c10-ba5f-f556744291eb.tmp
[0] Archive type: CAB (Microsoft)
--> F2913_HPProductSupportWebsite.url.C72289A0_334F_47B2_9027_660ACF342337
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Documents and Settings\Administrateur\Local Settings\Temp\610bfb0e-1d47-46d2-b227-fc89ae0c01ac.tmp
[0] Archive type: CAB (Microsoft)
--> F1308_hpobnz08.exe.843BC64F_8F28_4156_976C_445607111FBD
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\WINDOWS\Temp\2715aafa-4e3b-4be4-91af-5225e8a06485.tmp
[0] Archive type: CAB (Microsoft)
--> Windows6.0-KB949247-v6001-x86.cab
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\WINDOWS\Temp\387d0037-4049-4700-9bd4-ba48cbf2dda7.tmp
[0] Archive type: CAB (Microsoft)
--> 0
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed

End of the scan: 25 juillet 2009 14:39
Used time: 23:50 Minute(s)

The scan has been done completely.

4273 Scanned directories
186809 Files were scanned
0 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
1 Files cannot be scanned
186808 Files not concerned
7069 Archives were scanned
8 Warnings
1 Notes
7549 Objects were scanned with rootkit scan
5 Hidden objects were found
A voir également:

87 réponses

Utilisateur anonyme
 
ok ca sent le rootkit cette histoire(en general , quand MBAM plante.....) :


/!\ ATTENTION SUIVRE SCRUPULEUSEMENT A LA LETTRE CES INDICATIONS/!\

♦ Surtout , penses à l'enregistrement à renommer Combofix en "ton prenom.exe"


_________________________________________________________________
>Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
>>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
=====================================================</gras>

♦ On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

Avant d'utiliser ComboFix :
______________________________________________________________________
>> referme les fenêtres de tous les programmes en cours.
>> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
>>la protection en temps réel de ton Antivirus et de tes Antispywares,
>>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


♦ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

♦ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

>> Reviens sur le forum, et

♦ copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

0
tobor
 
J'ai essayé de le partir en mode sans échec et ça ne fonctionne pas.
0
Utilisateur anonyme
 
ok as-tu un msg d'erreur ?
0
tobor
 
Ça va pas bien, je clique sur ComboFix.exe la fenetre avec exécuter apparais je clique sur exécuter et il ne se passe rien...
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
tobor
 
La ligne 44 était pour Malwarebytes et pour la46 non je n'est pas de message d'erreur...
0
Utilisateur anonyme
 
tu as renommé Combofix comme demandé ?
0
tobor
 
Désolé j'avais oublié
0
Utilisateur anonyme
 
;)
0
tobor
 
ok je l'ai mit à la poubelle et j'ai recommencé et ça fonctionne...
0
Utilisateur anonyme
 
ne te sers pas du pc pendant que combofix tourne tu vas le mettre H.S
0
tobor
 
Bon le programme detecte un rootkit et est apparu un avertissement: PEV.exe Fichier endommagé et plus rien ne bouge...faut-il que je clique sur ok pour les 2 avertissements.
0
tobor
 
Non je me sert d'un autre ordi pour répondre...
0
Utilisateur anonyme
 
qui te signale PEV.exe ?
0
tobor
 
Un rectangle qui doit etre de windows l'autre rectangle pour le rootkot est de combofix
0
Utilisateur anonyme
 
tu as un rapport de Combo ?
0
tobor
 
ComboFix has detected the presence of rootkit activity and needs to reboot the machine Kindly note down on paper, the name of each file. We may need it later

C:/WINDOWS/system32/ESQULomafnxbbctjbfkatvaoyrodlgymkyrsp.dll
C:/WINDOWS/system32/driver/ESQUL......................................................sys
C:/WINDOWS/system32/ESQUL...........................................................dll

Quelque chose du genre...
0
tobor
 
non pas de rapport le programme est arreté...
0
Utilisateur anonyme
 
et tu as rebooté quand demandé ?
0
tobor
 
Non je vais le faire maintenant
0
Utilisateur anonyme
 
ca m etonne que combofix ne l'ai pas fait tout seul
0