Comment désinstaller alpha antivirus?

Bonjour,
J'ai été infecté par alpha antivirus et j'ai évidemment un problème pour le désinstaller. J'ai désinstallé le programme, fermé les processus dans le gestionnaire des taches mais rien n'y fait il me bloque encore mes pages internet. D'après ce que j'ai lu, je suis loin d'être le seul. J'ai installé RSIT et j'ai donc les 2 rapports log et info. Je suis pourtant incapable de les déchiffrer! Quelqu'un pourrait-il m'aider?? merci par avance
Configuration: Windows Vista Internet Explorer 7.0

5 réponses

  1. Contributeur
    Bonjour,

    télécharge GenProc http://www.alt-shift-return.org/Info/Fichiers/GenProc2633.zip sur ton bureau

    dézippe le dossier, double-clique sur GenProc.bat [img]http://forum.telecharger.01net.com/forum/[/img] et poste le contenu du rapport qui s'ouvre

    Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
    0
    1. ok merci beaucoup ezula. je suis desolé pour le retard dans la reponse mais alpha aantivirus bloque mes pages internet ce qui fait que j 'ai du trouver un autre ordi pour te répondre. je vasi essayer de t'envoyer les rapports très vite. merci encore.
      0
      1. Voici le rapport genproc, mais je ne comprends pas vraiment en quoi ce pourrait t'etre utile. Peut etre que tu voulait que je fasse les opérations présentées. Je le ferais rapidement puisque qu'internet a l'air de remarcher un peu sur mon ordi.

        Etape 1/ Télécharge :

        CCleaner (FileHippo). Ce logiciel va permettre de supprimer tous les fichiers temporaires. Lance-le et clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. Ferme le programme.

        Toolbar-S&D (Team IDN) sur ton Bureau.

        Redémarre en mode sans échec comme indiqué ICI ; Choisis ta session courante *** Documentation *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).

        Etape 2/

        Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

        Etape 3/

        Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

        Etape 4/

        Redémarre normalement et poste, dans la même réponse :

        - Le contenu du rapport TB.txt situé dans C:\ ;
        - Un nouveau rapport HijackThis ;
        - Un nouveau rapport GenProc ;

        Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

        Liste Ajout-Suppression de programmes - Arguments de la procédure
        0
        1. Contributeur
          je ne comprends pas vraiment en quoi ce pourrait t'etre utile

          c'est surtout à toi qu'elle peut être utile, suis cette procédure
          0
          1. Enfin, j'ai reussi à faire la procédure et à poster les rapports sans être bloqué.

            Voici le rapport TB.txt :

            -----------\\ ToolBar S&D 1.2.6 XP/Vista

            Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
            X86-based PC ( Uniprocessor Free : Mobile Intel(R) Pentium(R) 4 CPU 3.06GHz )
            BIOS : PhoenixBIOS 4.0 Release 6.0
            USER : Documentation ( Administrator )
            BOOT : Fail-safe boot
            Antivirus : Trend Micro Internet Security 14.00 (Activated)
            Firewall : Trend Micro PC-cillin Internet Security (Firewall) 14 (Activated)
            C:\ (Local Disk) - NTFS - Total:24 Go (Free:4 Go)
            D:\ (Local Disk) - NTFS - Total:7 Go (Free:4 Go)
            F:\ (CD or DVD)

            "C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
            Option : [2] ( 05/10/2009|19:39 )
            C:\WINDOWS\System32\f3PSSavr.scr
            C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll

            -----------\\ SUPPRESSION

            Supprime! - [Service] MyWebSearchService
            Supprime! - C:\Program Files\FunWebProducts\ScreenSaver
            Supprime! - C:\Program Files\FunWebProducts\Shared
            Supprime! - C:\Program Files\MyWebSearch\bar
            Supprime! - C:\DOCUME~1\DOCUME~1\Cookies\documentation@mywebsearch[1].txt
            Supprime! - C:\WINDOWS\System32\f3PSSavr.scr
            Supprime! - C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
            Supprime! - C:\Program Files\FunWebProducts
            Supprime! - C:\Program Files\MyWebSearch

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Start Page"="https://www.google.com/webhp?nord=1"
            "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            "Search Page"="https://www.google.com/?gws_rd=ssl"
            "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
            "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="https://www.msn.com/fr-fr/"

            --------------------\\ Recherche d'autres infections

            Aucune autre infection trouvée !

            1 - "C:\ToolBar SD\TB_1.txt" - 05/10/2009|19:41 - Option : [2]

            -----------\\ Fin du rapport a 19:41:24,15

            LE RAPPORT HIJACKTHIS :

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 19:54:14, on 05/10/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16705)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
            C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
            C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
            C:\Program Files\Apoint\Apoint.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\system32\ICO.EXE
            C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
            C:\Program Files\Sony\HotKey Utility\HKserv.exe
            C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
            C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
            C:\Program Files\WLAN CARD\WLANmon.exe
            C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\CyberLink\PowerCinema\PCMService.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
            C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
            C:\Program Files\Picasa2\PicasaMediaDetector.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
            C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
            C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
            C:\Program Files\Apoint\Apntex.exe
            C:\Program Files\Sony\HotKey Utility\HKWnd.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/webhp?nord=1
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
            O2 - BHO: &Helper - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\WINDOWS\system32\msnaoladdon.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
            O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
            O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
            O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
            O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
            O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
            O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
            O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
            O4 - HKLM\..\Run: [WLAN CARD WLAN Monitor] C:\Program Files\WLAN CARD\WLANmon.exe
            O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
            O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
            O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
            O4 - HKLM\..\Run: [D-Link D-Link Wireless N DWA-140] C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
            O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
            O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
            O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr
            O15 - Trusted Zone: *.sony-europe.com
            O15 - Trusted Zone: *.sonystyle-europe.com
            O15 - Trusted Zone: *.vaio-link.com
            O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://qp1.orion.education.fr/qp2.cab
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {5852F5ED-8BF4-11D4-A245-0080C6F74284} (isInstalled Class) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
            O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
            O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
            O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
            O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AvLib\PACSPTISVR.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AvLib\SPTISRV.exe
            O23 - Service: Tmntsrv - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe (file missing)
            O23 - Service: TmPfw - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe (file missing)
            O23 - Service: tmproxy - Trend Micro Inc. - (no file)
            O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
            O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
            O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
            O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
            O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
            O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
            O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
            O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
            O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
            O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
            O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
            0