Virus qui desinstalle avast et + - Page 2

Précédent
  • 1
  • 2
  1. kiki wall
     
    hello!

    Désolé, j'ai mis du temps à explorer toutes les possibilités.

    Alors, malgré les "10 techniques" de réparation de la connexion internet, je ne peux toujours pas me connecter (réseau non identifié, connectivité limitée ou inexistante). J'ai pas pu tout essayer, certaines techniques ne marchent pas sous vista, et pour les possibilités de réparation de l'os, j'ai pas le dvd d'install (on ne me l'a pas donné avec l'ordi).

    Je commence à désespérer!

    Si vous avez encore des idées, je suis preneur, et encore merci pour l'aide!!!!
    0
  2. kiki wall
     
    Petites précisions :
    - même en branchant le cable éthernet , la connexion est limitée (IPV4 et IPV6 limités, je n'atteins même pas le réseau local).
    - la box fonctionne parfaitement : j'arrive à me connecter à internet ( en wifi ou avec le cable) avec le portable de ma copine.
    - chose très bizarre : si le wifi du portable de ma copine est activé, alors mon portable arrive à se connecter jusqu'au réseau local (IPV4 local et IPV6 limité).

    Merci !!!
    0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok

    regarde ton manuel car de nombreux ordi sont fournis sans cd d'installation mais contiennent une partition contenant de quoi en créer une!!! il faut le faire dès l'achat du pc car sinon en cas de plantage il faut racheter une licence!

    Alors:
    1/ cré un cd d'installation en suivant ton manuel , si tu ne l'as pas regarde sur le net pour savoir, sinon cherche dans Demmarer où cela se situe

    2/
    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    - Va dans démarrer puis panneau de configuration
    - Double Clique sur l'icône "Comptes d'utilisateurs"
    - Clique ensuite sur désactiver et valide.

    télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau sous le nom de ccm.exe (avant de le mettre sur le bureau)

    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    0
  4. kiki wall
     
    hello!

    voilà le rapport. (normalement avast et norton sont désinstallés)

    ComboFix 10-03-02.02 - krushed wall 02/03/2010 22:51:28.1.2 - x86
    Microsoft® Windows Vista™ Professionnel 6.0.6000.0.1252.33.1036.18.2039.1103 [GMT 1:00]
    Lancé depuis: c:\users\krushed wall\Desktop\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
    AV: avast! Antivirus *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
    SP: AntiVir Desktop *disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
    SP: avast! Antivirus *disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
    SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\$recycle.bin\S-1-5-21-1481268058-3463252218-2816422393-500
    c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500
    c:\windows\system32\ACCWIZ.DLL
    c:\windows\system32\MSIMRT.DLL
    c:\windows\system32\MSIMUSIC.DLL

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2010-02-02 au 2010-03-02 ))))))))))))))))))))))))))))))))))))
    .

    2010-03-02 22:01 . 2010-03-02 22:01 -------- d-----w- c:\users\krushed wall\AppData\Local\temp
    2010-03-02 22:01 . 2010-03-02 22:01 -------- d-----w- c:\users\moi\AppData\Local\temp
    2010-03-02 22:01 . 2010-03-02 22:01 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-03-01 13:47 . 2010-03-01 13:47 -------- d-----w- c:\program files\XP TCPIP Repair
    2010-03-01 13:41 . 2010-03-01 13:38 1413120 ----a-w- C:\winsockfix.exe
    2010-02-24 14:54 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2010-02-23 16:25 . 2010-02-23 16:25 1887 ----a-w- C:\FindyKill_Upload_Me_moi.zip
    2010-02-23 13:07 . 2010-02-23 16:25 -------- d-----w- C:\FyK
    2010-02-23 11:05 . 2010-02-23 15:20 -------- d-----w- c:\program files\a-squared Free
    2010-02-17 18:11 . 2010-02-28 13:46 -------- d-----w- c:\programdata\Alwil Software
    2010-02-17 18:11 . 2010-02-17 18:11 -------- d-----w- C:\TEMP
    2010-02-17 15:07 . 2010-02-17 15:03 42092016 ----a-w- C:\setup_av_free_fre.exe

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-03-02 21:57 . 2006-11-02 15:47 690832 ----a-w- c:\windows\system32\perfh00C.dat
    2010-03-02 21:57 . 2006-11-02 15:47 117572 ----a-w- c:\windows\system32\perfc00C.dat
    2010-03-02 21:48 . 2007-06-07 12:53 1660 ----a-w- c:\windows\bthservsdp.dat
    2010-02-28 16:02 . 2010-01-12 21:02 -------- d-----w- c:\users\krushed wall\AppData\Roaming\gtk-2.0
    2010-02-28 13:50 . 2007-06-06 10:37 -------- d-----w- c:\programdata\Symantec
    2010-02-28 13:50 . 2007-06-06 10:37 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2010-02-28 13:50 . 2007-06-06 10:40 -------- d-----w- c:\program files\Norton Internet Security
    2010-02-28 13:48 . 2010-01-20 22:35 -------- d-----w- c:\programdata\eMule
    2010-02-23 16:04 . 2008-05-18 07:58 -------- d-----w- c:\program files\DAEMON Tools Lite
    2010-02-17 18:14 . 2007-10-29 20:06 -------- d-----w- c:\program files\Alwil Software
    2010-02-17 14:58 . 2010-01-30 11:08 -------- d-----w- c:\program files\Mattel Interactive
    2010-01-26 13:14 . 2009-12-02 08:38 -------- d-----w- c:\users\krushed wall\AppData\Roaming\FileZilla
    2010-01-23 19:22 . 2009-06-22 15:39 -------- d-----w- c:\users\krushed wall\AppData\Roaming\dvdcss
    2010-01-22 08:15 . 2009-09-16 12:49 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-01-14 10:12 . 2009-10-05 09:53 181120 ------w- c:\windows\system32\MpSigStub.exe
    2010-01-14 09:15 . 2007-06-07 13:25 -------- d-----w- c:\programdata\Microsoft Help
    2010-01-14 09:11 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-01-12 20:51 . 2010-01-12 20:50 -------- d-----w- c:\program files\GIMP-2.0
    2009-12-18 12:52 . 2010-01-22 08:31 832512 ----a-w- c:\windows\system32\wininet.dll
    2009-12-18 12:48 . 2010-01-22 08:31 56320 ----a-w- c:\windows\system32\iesetup.dll
    2009-12-18 12:48 . 2010-01-22 08:31 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-12-18 12:48 . 2010-01-22 08:31 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
    2009-12-18 12:46 . 2010-01-22 08:31 72704 ----a-w- c:\windows\system32\admparse.dll
    2009-12-18 10:18 . 2010-01-22 08:31 26624 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-12-18 08:45 . 2010-01-22 08:31 48128 ----a-w- c:\windows\system32\mshtmler.dll
    2009-05-13 21:55 . 2009-05-13 21:55 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-13 21:55 . 2009-05-13 21:55 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-23 1232896]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-06-06 1006264]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 4431872]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
    "MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2007-04-19 561152]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2010-02-23 583048]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
    "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-02-23 115816]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-25 110592]
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "UacDisableNotify"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer2"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1546274544-2757883488-1291118467-1000]
    "EnableNotificationsRef"=dword:00000001

    R0 iaNvStor;Intel(R) Turbo Memory Technology NAND Controller;c:\windows\System32\drivers\iaNvStor.sys [06/06/2007 12:34 210432]
    R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [20/11/2006 14:14 38400]
    R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [09/03/2007 13:01 35968]
    R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20071220.001\IDSvix86.sys [26/12/2007 18:22 180272]
    R3 MGHwCtrl;MGHwCtrl;c:\windows\System32\drivers\MGHwCtrl.sys [06/06/2007 11:32 19456]
    S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [18/05/2008 08:54 717296]
    S2 NishService;SCM Driver Daemon;c:\program files\System Control Manager\edd.exe [06/06/2007 11:32 40960]
    S3 DTT200U;DVB200 USB receiver Driver;c:\windows\System32\drivers\DTT200U.sys [24/04/2008 20:28 18432]
    S3 DTT200ULD;DVB200 USB receiver firmware loader;c:\windows\System32\drivers\DTT200ULD.sys [24/04/2008 20:26 18560]
    S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [16/09/2009 13:48 54632]
    S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
    S3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [09/01/2007 15:32 38200]
    S3 US122;US122 Driver;c:\windows\System32\drivers\US122.sys [25/10/2007 16:22 131968]
    S3 US122DL;US122 Firmware Downloader;c:\windows\System32\drivers\US122DL.sys [25/10/2007 16:22 18304]
    S3 Us122WdmService;US122 Wdm Audio;c:\windows\System32\drivers\US122Wdm.sys [25/10/2007 16:22 39168]
    S4 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [23/02/2010 12:05 1858144]

    --- Autres Services/Pilotes en mémoire ---

    *NewlyCreated* - COMHOST

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
    bthsvcs REG_MULTI_SZ BthServ
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.msi.com.tw
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\users\krushed wall\AppData\Roaming\Mozilla\Firefox\Profiles\kifdo0bn.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.blackle.com/
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- PARAMETRES FIREFOX ----
    FF - user.js: yahoo.homepage.dontask - true.
    - - - - ORPHELINS SUPPRIMES - - - -

    HKCU-Run-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
    HKLM-Run-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
    HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe
    AddRemove-realMYST Interactive 3D Edition - c:\program files\Mattel Interactive\realMYST Interactive 3D Edition\Uninst.isu

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-03-02 23:01
    Windows 6.0.6000 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Heure de fin: 2010-03-02 23:05:33
    ComboFix-quarantined-files.txt 2010-03-02 22:05

    Avant-CF: 1 816 117 248 octets libres
    Après-CF: 4 839 997 440 octets libres

    - - End Of File - - 3465DCA08533D159824035B191E0D39A
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    il reste du norton et de l'avast

    pour bien virer avast:

    https://www.avast.com/fr-fr/uninstall-utility

    pour virer norton:

    http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

    https://www.commentcamarche.net/faq/2453-supprimer-desinstaller-norton-antivirus-norton-internet-security

    _____________________

    comment va ton pc?
    0
  7. kiki wall
     
    Super ! Tout remarche à la perfection.
    La désinstallation complète de norton et d'avast a réparé la connexion. J'ai refait tourner combofix derrière juste au cas où. Puis j'ai remis le contrôle utilisateur, résinstallé Avast depuis et tout refonctionne parfaitement.

    Merci beaucoup!!!
    0
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    pour virer ce qui a été utilisé lance tools cleaner
    0
Précédent
  • 1
  • 2