Précédent
- 1
- 2
- 3
- 4
- 5
-
ok daccor moi aussi je fais cela et jtenvoie par email sur ccm
bonne nuit et merci -
-
Pour plus de lisibilité, je laisse tes messages utiles.
Voici les rapports (si ça intéresse certains) :
a-squared 4.5.0.50 2010.03.16 Trojan-Dropper!IK AhnLab-V3 5.0.0.2 2010.03.16 Win-Trojan/LmirHack.139908 AntiVir 8.2.1.180 2010.03.16 TR/Dropper.Gen Antiy-AVL 2.0.3.7 2010.03.16 - Authentium 5.2.0.5 2010.03.16 W32/VBTrojan.Dropper.2!Maximus Avast 4.8.1351.0 2010.03.16 Win32:Trojan-gen Avast5 5.0.332.0 2010.03.16 Win32:Trojan-gen AVG 9.0.0.787 2010.03.16 Dropper.Generic.AXOC BitDefender 7.2 2010.03.16 - CAT-QuickHeal 10.00 2010.03.15 Trojan.Agent.ATV ClamAV 0.96.0.0-git 2010.03.16 - Comodo 4285 2010.03.16 UnclassifiedMalware DrWeb 5.0.1.12222 2010.03.16 - eSafe 7.0.17.0 2010.03.16 - eTrust-Vet 35.2.7365 2010.03.16 - F-Prot 4.5.1.85 2010.03.16 W32/VBTrojan.Dropper.2!Maximus F-Secure 9.0.15370.0 2010.03.16 - Fortinet 4.0.14.0 2010.03.15 - GData 19 2010.03.16 Win32:Trojan-gen Ikarus T3.1.1.80.0 2010.03.16 Trojan-Dropper Jiangmin 13.0.900 2010.03.16 - K7AntiVirus 7.10.998 2010.03.15 - Kaspersky 7.0.0.125 2010.03.16 - McAfee 5921 2010.03.15 - McAfee+Artemis 5921 2010.03.15 Artemis!55247E0D4E35 McAfee-GW-Edition 6.8.5 2010.03.16 Trojan.Dropper.Gen Microsoft 1.5605 2010.03.16 - NOD32 4949 2010.03.16 - Norman 6.04.08 2010.03.16 - nProtect 2009.1.8.0 2010.03.16 - Panda 10.0.2.6 2010.03.16 Suspicious file PCTools 7.0.3.5 2010.03.15 - Prevx 3.0 2010.03.16 High Risk Cloaked Malware Rising 22.39.01.04 2010.03.16 - Sophos 4.51.0 2010.03.16 Mal/VBDrop-G Sunbelt 5916 2010.03.16 - Symantec 20091.2.0.41 2010.03.16 Suspicious.ADH TheHacker 6.5.2.0.234 2010.03.16 - TrendMicro 9.120.0.1004 2010.03.16 - VBA32 3.12.12.2 2010.03.16 - ViRobot 2010.3.16.2230 2010.03.16 - VirusBuster 5.0.27.0 2010.03.16 - pour le 2 a-squared 4.5.0.50 2010.03.16 Trojan-Dropper!IK AhnLab-V3 5.0.0.2 2010.03.16 Win-Trojan/LmirHack.263300 AntiVir 8.2.1.180 2010.03.16 TR/Dropper.Gen Antiy-AVL 2.0.3.7 2010.03.16 - Authentium 5.2.0.5 2010.03.16 W32/VBTrojan.Dropper.2!Maximus Avast 4.8.1351.0 2010.03.16 Win32:Trojan-gen Avast5 5.0.332.0 2010.03.16 Win32:Trojan-gen AVG 9.0.0.787 2010.03.16 Dropper.Generic.AXOC BitDefender 7.2 2010.03.16 - CAT-QuickHeal 10.00 2010.03.15 Trojan.Agent.ATV ClamAV 0.96.0.0-git 2010.03.16 - Comodo 4285 2010.03.16 UnclassifiedMalware DrWeb 5.0.1.12222 2010.03.16 - eSafe 7.0.17.0 2010.03.16 - eTrust-Vet 35.2.7365 2010.03.16 - F-Prot 4.5.1.85 2010.03.16 W32/VBTrojan.Dropper.2!Maximus F-Secure 9.0.15370.0 2010.03.16 - Fortinet 4.0.14.0 2010.03.15 - GData 19 2010.03.16 Win32:Trojan-gen Ikarus T3.1.1.80.0 2010.03.16 Trojan-Dropper Jiangmin 13.0.900 2010.03.16 - K7AntiVirus 7.10.998 2010.03.15 - Kaspersky 7.0.0.125 2010.03.16 - McAfee 5921 2010.03.15 - McAfee+Artemis 5921 2010.03.15 Artemis!5785110A76A2 McAfee-GW-Edition 6.8.5 2010.03.16 Trojan.Dropper.Gen Microsoft 1.5605 2010.03.16 - NOD32 4949 2010.03.16 - Norman 6.04.08 2010.03.16 - nProtect 2009.1.8.0 2010.03.16 - Panda 10.0.2.6 2010.03.16 - PCTools 7.0.3.5 2010.03.15 - Prevx 3.0 2010.03.16 - Rising 22.39.01.04 2010.03.16 - Sophos 4.51.0 2010.03.16 Mal/VBDrop-G Sunbelt 5916 2010.03.16 - Symantec 20091.2.0.41 2010.03.16 Suspicious.ADH TheHacker 6.5.2.0.234 2010.03.16 - TrendMicro 9.120.0.1004 2010.03.16 - VBA32 3.12.12.2 2010.03.16 - ViRobot 2010.3.16.2230 2010.03.16 - VirusBuster 5.0.27.0 2010.03.16 - et pour le 3 a-squared 4.5.0.50 2010.03.16 - AhnLab-V3 5.0.0.2 2010.03.16 - AntiVir 8.2.1.180 2010.03.16 - Antiy-AVL 2.0.3.7 2010.03.16 - Authentium 5.2.0.5 2010.03.16 - Avast 4.8.1351.0 2010.03.16 - Avast5 5.0.332.0 2010.03.16 - AVG 9.0.0.787 2010.03.16 - BitDefender 7.2 2010.03.16 - CAT-QuickHeal 10.00 2010.03.15 - ClamAV 0.96.0.0-git 2010.03.16 - Comodo 4285 2010.03.16 - DrWeb 5.0.1.12222 2010.03.16 - eSafe 7.0.17.0 2010.03.16 - eTrust-Vet 35.2.7365 2010.03.16 - F-Prot 4.5.1.85 2010.03.16 - F-Secure 9.0.15370.0 2010.03.16 - Fortinet 4.0.14.0 2010.03.15 - GData 19 2010.03.16 - Ikarus T3.1.1.80.0 2010.03.16 - Jiangmin 13.0.900 2010.03.16 - K7AntiVirus 7.10.998 2010.03.15 - Kaspersky 7.0.0.125 2010.03.16 - McAfee 5921 2010.03.15 - McAfee+Artemis 5921 2010.03.15 - McAfee-GW-Edition 6.8.5 2010.03.16 Heuristic.BehavesLike.Win32.Suspicious.H Microsoft 1.5605 2010.03.16 - NOD32 4949 2010.03.16 - Norman 6.04.08 2010.03.16 - nProtect 2009.1.8.0 2010.03.16 - Panda 10.0.2.6 2010.03.16 - PCTools 7.0.3.5 2010.03.15 - Prevx 3.0 2010.03.16 - Rising 22.39.01.04 2010.03.16 - Sophos 4.51.0 2010.03.16 - Sunbelt 5916 2010.03.16 - Symantec 20091.2.0.41 2010.03.16 Reser.Reputation.1 TheHacker 6.5.2.0.234 2010.03.16 - TrendMicro 9.120.0.1004 2010.03.16 - VBA32 3.12.12.2 2010.03.16 - ViRobot 2010.3.16.2230 2010.03.16 - VirusBuster 5.0.27.0 2010.03.16 -
Quel est le fichier que tu as analysé en dernier ? le 3.exe ? ou le troisième de la liste à savoir 2.exe ?
-
ba c dans lordre
quand tu voi pour le de
gerhrtjhrj
yjtejytyjtyj ect
ca c pour le deux
puis quand tu voie pour le 3
sgregherpgh regiherpu ect
c pour le trois-
Pas compris ta chaine de caractères incompréhensible mais ce n'est pas grave.
Envoie le fichier concerné par :
et pour le 3
donc le dernier ici :
https://www.avira.com/
Ensuite, une fois que c'est fait, supprime ces trois fichiers manuellement.
(Ne les exécute pas malencontreusement !)
-
-
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question -
-
dsl je comprend pas ton site en aussi l'anglais un peu mais pas pour lire un site englais
dsl dsl -
-
-
-
heu assi la jfais une annalyse avec mon pc il detecte 3 virus mais tkt il va les usprimer
-
analyse avec eset nod32 v4
et voila le rapport
Logfile of random's system information tool 1.06 (written by random/random)
Run by Francis at 2010-03-16 19:51:59
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 43 GB (54%) free of 79 GB
Total RAM: 511 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:52:28, on 16/03/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\MESSAG~1\StartMessager.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Marc Dorcel\nclaunch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\Francis\Bureau\RSIT.exe
C:\Program Files\Trend Micro\Francis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [tppoll] C:\Program Files\Topro\tppoll.exe
O4 - HKCU\..\Run: [nclaunch] C:\Program Files\Marc Dorcel\nclaunch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSAG~1\Messager Wanadoo.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C34CF7D3-16A7-4351-9D0E-79F522564F0C}: NameServer = 81.253.149.9 80.10.246.3
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
-
-
dsl si vous poster car g vu que vous poster mais je ram a mort et jvois pas vos message poster
-
Tu posteras bien le rapport Nod32 à la fin de l'analyse ?!
******
Je vais manger, je te prépare une procédure tout à l'heure... -
heu il est ou le rapport nod et puis je ramer tel men gt a 70 pourcant g arreter car ma connextion etait rop instable
et bonne appeti-
-
-
J'ai vu ton rapport par MP.
Je ne le posterai pas, ce n'est pas utile.
La prochaine fois, tu les posteras directement ici.
Les 3 détections = restauration + Quarantaine de USB Fix.
Rien d'inquiétant.
J'ai pris note e ton absence.
J'attends ton retour pour finir la désinfection proprement.
En attendant, ne pas utiliser les outils utilisés (RSIT, USBFix, ...). (Sauf MBAM si tu veux).
-
-
-
heu pour les trois virus jprefaire les laisser dans la quarezntaine de eset ca ne vous dreange pas
-
Si tu veux, mais tu peux les supprimer, c'est infectieux :D
****
Tu veux terminer maintenant ? (Il reste un script OTM à faire)*.
*Ce qui est en italique, c'est pour moi ;-). -
heu tu peux presiser et pour les uprimmer de eset jfais comeme mais c en securiter en quarentaine comme ou pas
-
Précédent
- 1
- 2
- 3
- 4
- 5