84 fichiers infecters par 4 virus .... HELP!! - Page 2

Précédent
  • 1
  • 2
  1. babas57
     
    Re,

    J'ai deja essayé mais comme je te l'ais dit plus haut si je fait cette manip le pc se relance... Pire qu'avant.

    La seule chose à laquelle j'ai accés c'est la restauration par HP car je suppose qu'il reboote sur la partition D: de mon disque dur (partition d'origine avec la restauration windows par HP)

    Salut
    0
  2. Utilisateur anonyme
     
    re,
    sinon tu as essayer de reinstaller avec le cd?

    a+
    0
  3. babas57
     
    Re,

    Voila j'ai reussit a relancer le pc j'ai fait un hijackthis et voila le resultat:

    Logfile of HijackThis v1.99.1
    Scan saved at 19:13:38, on 14/11/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\tftp.exe
    C:\Documents and Settings\Propriétaire\Bureau\HijackThis.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ftp.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://fr8.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [NAV CfgWiz] c:\PROGRA~1\NORTON~1\Cfgwiz.exe /R
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    tien moi au courant
    0
  4. Utilisateur anonyme
     
    salut
    relance hijack this, coche ceci et sur fix checked
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    supprime
    C:\WINDOWS\ALCXMNTR.EXE

    et
    Lance ce scan en ligne:
    http://www.bitdefender.fr/scan8/ie.html
    Copie/colle le rapport

    A+
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. babas57
     
    Re,

    J'ai reussit à télécharger antivir et a scanner le pc.
    Je ne l'ai pas fait avec bitdefender car à cause des virus ma connexion internet ressemble à du 28Kb/s...

    Voila le rapport antivir:

    Creation date of the report file: lundi 14 novembre 2005 21:15

    AntiVir®/XP (2000 + NT) PersonalEdition Classic
    Build 1114 of 04.11.2005
    Mainprogram 6.32.00.51 of 03.11.2005
    VDF file 6.32.14.16 (0) of 07.11.2005

    This program is for PERSONAL USE only.
    Any other use is PROHIBITED.
    Informations regarding commercial versions of AntiVir may be obtained from:
    www.hbedv.com.

    Scanning for 244480 virus strains and unwanted programs.

    Licensed for: AntiVir Personal Edition
    Serial number: 0000149991-WURGE-0001

    Please enter the workstation and
    contact name with phone number in this form:

    Name ___________________________________________

    Street ___________________________________________

    Town ___________________________________________

    Phone/Fax ___________________________________________

    Email ___________________________________________

    Platform: Windows NT Workstation
    Windows version: 5.1 Build 2600 (Service Pack 1)
    Username: Propriétaire
    Computername: BASTIEN
    Processor: Pentium
    Working memory: 523632 KB free

    Version information:
    AVWIN.DLL : 6.32.00.51 561192 04.11.2005 07:50:54
    AVEWIN32.DLL : 6.32.0.57 954880 14.10.2005 15:08:24
    AVGNT.EXE : 6.32.00.02 180327 03.11.2005 17:06:56
    AVGUARD.EXE : 6.32.00.12 208424 03.11.2005 17:06:58
    GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 10:24:12
    AVGCMSG.DLL : 6.32.00.01 295029 03.11.2005 17:06:58
    AVGNTDW.SYS : 6.31.00.01 32896 29.04.2005 08:07:16
    AVPACK32.DLL : 6.32.00.02 319528 03.11.2005 16:57:42
    AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 17:10:20
    AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 17:10:22
    AVSched32.EXE : 6.32.00.01 110632 20.09.2005 14:16:26
    AVSched32.DLL : 6.30.00.00 122880 01.02.2005 10:24:12
    AVREG.DLL : 6.31.00.05 41000 07.09.2005 16:34:50
    AVRep.DLL : 6.32.00.152 1470504 07.11.2005 08:31:40
    INETUPD.EXE : 6.32.00.53 262203 04.11.2005 07:49:30
    INETUPD.DLL : 6.32.00.53 143360 04.11.2005 07:49:30
    CTL3D32.DLL : 2.31.000 27136 21.01.2003 16:09:00
    MFC42.DLL : 6.00.8665.0 995383 21.01.2003 19:14:00
    MSVCRT.DLL : 7.0.2600.1106 (xpsp1.020828-1920
    MSVCRT.DLL : 7.0.2600.1106 323072 21.01.2003 16:01:00
    CTL3DV2.DLL : No information

    Configuration file:

    Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI
    Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG
    Start path: C:\Program Files\AVPersonal
    Command line:
    Start mode: unknown

    Mode of report file:
    [ ] Do not create report
    [X] Overwrite report
    [ ] Append new report

    Data in report file:
    [X] Infected files
    [ ] Infected files with paths
    [ ] All scanned files
    [ ] Full information

    Abridge report file:
    [ ] Abridge report file

    Warnings in report:
    [X] Access denied/file locked
    [X] Wrong file size in directory
    [X] Wrong creation time in directory
    [ ] COM file is too large
    [X] Invalid start address
    [X] Invalid EXE header
    [X] Possibly damaged

    Summary report:
    [X] Create summary report
    Output file: AVWIN.ACT
    Maximum number of entries: 100

    Where to search:
    [X] Memory
    [X] Boot record of selected drives
    [ ] Report unknown boot sectors
    [ ] All files
    [X] Program files
    Extensions: .386 .?HT* .ACM .ADE .ADP .ANI .APP .ASD .ASF .ASP .ASX .AWX .AX .BAS .BAT .BIN .BOO .CDF .CHM .CLASS .CMD .CNV .COM .CPL .CRT .CSH .DLL .DLO .DO? .DRV .EMF .EML .EXE* .FLT .FOT .HLP .HT* .INF .INI .INS .ISP .J2K .JAR .JFF .JFI .JFIF .JIF .JMH .JNG .JP2 .JPE .JPEG .JPG .JS* .JSE .LNK .MD? .MDB .MOD .MS? .NWS .OBJ .OCX .OLB .OSD .OV? .PCD .PDR .PGM .PHP .PIF .PKG .PL* .PNG .POT .PPS .PPT .PRG .RAR .REG .RPL .RTF .SBF .SCR .SCRIPT .SCT .SH .SHA .SHB .SHS .SHTM* .SPL .SWF .SYS .TLB .TMP .TSP .TTF .URL .VB? .VCS .VLM .VXD .VXO .WIZ .WLL .WMD .WMS .WMZ .WPC .WSC .WSF .WSH .WWK .XL? .XML .ZIP

    Response in case of a detection:
    [X] Repair with prompt
    [ ] Repair without prompt
    [ ] Delete with prompt
    [ ] Delete without prompt
    [ ] Write in report file only
    [X] Acoustic alarm

    Response in case of destroyed files:
    [X] Delete with prompt
    [ ] Delete without prompt
    [ ] Ignore

    Response in case of destroyed files:
    [X] No change
    [ ] Current system time
    [ ] Correct date

    Drag&drop settings:
    [X] Scan subdirectories

    Profile settings:
    [X] Scan subdirectories

    Archive options
    [X] Search archive
    [X] All archive types

    Miscellaneous options:
    Temporary path: %TEMP% -> C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp
    [X] Overwrite infected files
    [ ] Detect idle time
    [X] Allow interruptions of scan
    [ ] Load AVWin®/NT Guard on System start

    General settings:
    [X] Save options on exiting AntiVir
    Priority: medium

    Drives:
    A: Floppy drive
    C: Hard disk
    D: Hard disk
    E: CD-ROM
    F: CD-ROM

    Start of scan: lundi 14 novembre 2005 21:15

    Memory test OK
    Master boot record of hard disk HD0 OK
    Boot record of drive C: OK

    Access denied! Error during file opening!
    Error code: 0x0002
    C:\

    WARNING! Access error/file locked!
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery
    AbetterInternetAurora.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    AlexaRelated.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    AlexaRelated1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    CometCursors.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    CometCursors1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    DyFuCA.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechISTbar.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechISTbar1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechISTsvc.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechPowerScan.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechSideFind.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechYSB.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechYSB1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechYSB2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechYSB3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechYSB4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    ISearchTechYSB5.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    MediaMotor.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    MediaMotor1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    MediaMotor2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    nCase.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant5.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsSearchAssistant6.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango10.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango11.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango12.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango2.zip
    ArchiveType: ZIP
    SolutionsZango3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango5.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango6.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango7.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango8.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SolutionsZango9.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SurfAccuracy.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    SurfAccuracy1.zip
    ArchiveType: ZIP
    WindowsAdTools.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusDisableNotify.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusDisableNotify1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusDisableNotify2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusDisableNotify3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusDisableNotify4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusOverride.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusOverride1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusOverride2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusOverride3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterAntiVirusOverride4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallDisableNotify.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallDisableNotify1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallDisableNotify2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallDisableNotify3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallDisableNotify4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallOverride.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallOverride1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallOverride2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallOverride3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterFirewallOverride4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterSPUpdate.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterSPUpdate1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterSPUpdate2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterSPUpdate3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterSPUpdate4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterTaskManager.zip
    ArchiveType: ZIP
    WindowsSecurityCenterTaskManager1.zip
    ArchiveType: ZIP
    WindowsSecurityCenterUpdateDisableNotify.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterUpdateDisableNotify1.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterUpdateDisableNotify2.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterUpdateDisableNotify3.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    WindowsSecurityCenterUpdateDisableNotify4.zip
    ArchiveType: ZIP
    NOTE! The whole archive is password protected
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0PUNGDAF
    mtrslib2[1].js
    [DETECTION] Contains signature of the Java script virus JS/Small.AG
    WAS DELETED!
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\8HEJ4X4Z
    ak47[1].exe
    [DETECTION] Is the Trojan horse TR/LowZones.K.6
    WAS DELETED!
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\UX4RM581
    mtrslib2[1].js
    [DETECTION] Contains signature of the Java script virus JS/Small.AG
    WAS DELETED!
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\WLOHILGB
    MediaTicketsInstaller[1].cab
    ArchiveType: CAB (Microsoft)
    --> MediaTicketsInstaller.ocx
    NOTE! Bad header
    --> MediaTicketsInstaller.INF
    NOTE! Bad header
    C:\Program Files\WinRAR
    rarnew.dat
    ArchiveType: RAR
    NOTE! The archive is created by multiple volumes
    Error! Could not change directory: System Volume Information
    C:\WINDOWS
    F ma.exe
    [DETECTION] Contains signature of the dropper DR/QLowZones.1
    WAS DELETED!
    IEMonitor.ocx
    [DETECTION] Contains signature of the dropper DR/QLowZones.2
    WAS DELETED!
    msstl.exe
    [DETECTION] Contains signature of the worm WORM/SdBot.64512.14
    WAS DELETED!
    C:\WINDOWS\system32
    jkkjg.dll
    [DETECTION] Is the Trojan horse TR/Dldr.ConHook.L
    WAS DELETED!
    mllmj.dll
    [DETECTION] Is the Trojan horse TR/Dldr.ConHook.L
    WAS DELETED!
    rdriv.sys
    [DETECTION] Is the Trojan horse TR/Rootkit.L
    WAS DELETED!
    remon.sys
    [DETECTION] Is the Trojan horse TR/Rootkit.Agent.AB
    WAS DELETED!
    srshostu.exe
    [DETECTION] Is the Trojan horse TR/Proxy.Agent.CM
    WAS DELETED!
    ssqro.dll
    [DETECTION] Is the Trojan horse TR/Dldr.ConHook.L
    WAS DELETED!
    ssqrr.dll
    [DETECTION] Is the Trojan horse TR/Dldr.ConHook.L
    Could not be deleted!
    syshost.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Small.bsj
    WAS DELETED!
    winl0gonn.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Small.bsj
    WAS DELETED!
    wirl0g0n.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Small.bsj
    WAS DELETED!
    C:\WINDOWS\system32\config
    default
    Access denied! Error during file opening!
    Error code: 0x000D
    WARNING! Access error/file locked!
    SAM
    Access denied! Error during file opening!
    Error code: 0x000D
    WARNING! Access error/file locked!
    SECURITY
    Access denied! Error during file opening!
    Error code: 0x000D
    WARNING! Access error/file locked!
    software
    Access denied! Error during file opening!
    Error code: 0x000D
    WARNING! Access error/file locked!
    system
    Access denied! Error during file opening!
    Error code: 0x000D
    WARNING! Access error/file locked!

    End of scan: lundi 14 novembre 2005 22:06
    Time taken: 50:42 min

    3038 directories were scanned
    75832 files were scanned
    7 warning messages were issued
    15 files were deleted
    0 files were repaired
    16 detections

    J'ai toujours des virus mais ca a l'air d'aller un peu mieux.

    Voila aussi le dernier rapport hijackthis:

    Logfile of HijackThis v1.99.1
    Scan saved at 22:18:05, on 14/11/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\AVPersonal\AVGNT.EXE
    C:\Program Files\AVPersonal\AVGUARD.EXE
    C:\Program Files\AVPersonal\AVWUPSRV.EXE
    C:\WINDOWS\modlb.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\shost.exe
    c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    C:\WINDOWS\REGEDIT.EXE
    C:\WINDOWS\System32\msiexec.exe
    C:\WINDOWS\System32\MsiExec.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\Propriétaire\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://fr8.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\ssqrr.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [MS Unix Binary] msnq3insller.exe
    O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
    O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
    O4 - HKLM\..\RunServices: [MS Unix Binary] msnq3insller.exe
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [MS Unix Binary] msnq3insller.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102501/housecall.trendmicro.com/housecall/xscan53.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: ssqrr - C:\WINDOWS\SYSTEM32\ssqrr.dll
    O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
    O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
    O23 - Service: BusinessC (BusinessContinuity) - Unknown owner - C:\WINDOWS\msstl.exe (file missing)
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Mod Libary (modlb) - Unknown owner - C:\WINDOWS\modlb.exe
    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINDOWS\shost.exe

    que faire maintenant, car antivir n'arrete pas de sonner pour le fichier ssqrr.dll

    j'attend
    0
  7. Utilisateur anonyme
     
    re
    bha oui logique, nouvelle infection, pire en plus
    fais chier grrrrrr

    je vois que tu as desinstaller bidfender, tant mieux

    a+
    0
  8. Utilisateur anonyme
     
    Salut,

    Imprime, ou enregistre ceci dans le bloc note pour ne rien oublier.

    1/

    télécharge : process xp ici:
    http://www.sysinternals.com/files/procexpnt.zip

    Télécharge: Pocket Killbox ici
    http://www.downloads.subratam.org/KillBox.exe

    :: Démo d utilisation (merci a Balltrap34 pour cette réalisation) ::
    http://pageperso.aol.fr/balltrap34/killbox.htm

    2/

    Déconnecte toi du net.
    Ferme tous les programmes en cours (média player, internet explorer, ...etc)

    Dézippe (clic droit > extraire) process xp et double clic sur processxp.exe

    * Dans la fenêtre principale de processxp double clic sur winlogon.exe
    Dans la nouvelle fenêtre qui s'ouvre clique sur threads
    sélectionne seulement les lignes qui contiennent ssqrr.dll puis clique sur kill pour chacune des lignes trouvées.
    une fois fait, valide avec ok

    * Dans la fenêtre principale de processxp double clic sur explorer.exe
    Dans la nouvelle fenêtre qui s'ouvre clique sur threads
    sélectionner seulement les lignes qui contiennent ssqrr.dll puis clique sur kill pour chacune des lignes trouvées.
    une fois fait, valide avec ok

    3/

    puis lancer HijackThis:

    clique sur "do a system scan only"

    * Cocher la case au début de ces lignes:

    O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\ssqrr.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [MS Unix Binary] msnq3insller.exe

    O4 - HKLM\..\RunServices: [MCX Update] wisp.exe

    O4 - HKLM\..\RunServices: [MS Unix Binary] msnq3insller.exe

    O4 - HKCU\..\Run: [MS Unix Binary] msnq3insller.exe

    O20 - Winlogon Notify: ssqrr - C:\WINDOWS\SYSTEM32\ssqrr.dll

    O23 - Service: BusinessC (BusinessContinuity) - Unknown owner - C:\WINDOWS\msstl.exe (file missing)

    O23 - Service: Mod Libary (modlb) - Unknown owner - C:\WINDOWS\modlb.exe

    O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINDOWS\shost.exe

    * Valider avec fix checked

    ----------------------------------------------------------------------------
    ¤Recherche et supprime ceci:
    attention seulement les fichiers (si présents).

    wisp.exe
    msnq3insller.exe
    C:\WINDOWS\msstl.exe
    C:\WINDOWS\modlb.exe
    C:\WINDOWS\shost.exe

    ----------------------------------------------------------------------------
    ¤Arrête ces services :

    Clique sur Démarrer->exécuter->tape: services.msc

    Double-clique: Service: BusinessC

    Règle-le sur "Arrêté" et "Désactivé".

    Fais de meme avec ceci
    Mod Libary
    Service Hosts

    5/

    Double clic sur killbox.exe (Pocket Killbox)

    - coche: delete on reboot
    - Dans "Full Path of File to Delete"
    copie et colle:

    C:\WINDOWS\SYSTEM32\ssqrr.dll

    - clique sur la croix rouge
    - une fenêtre va apparaître pour confirmation clique sur YES
    - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

    Laisse le pc redémarrer.
    Et après reposte un log HijackThis.
    0
Précédent
  • 1
  • 2