Suspition de virus, Comment savoir ?

Résolu
Utilisateur anonyme -  
 Utilisateur anonyme -
Bonjour à tous,

hey bien voila, je pense avoir un virus sur mon ordinateur, mais mon antivirus (avast) ne trouve rien...
Plusieurs signe me le font penser :
-Au démarrage de mon ordianteur, windows me fait un scan disck à chaque fois, et ce dernier plante...
-Dans le coins en bas à droite de l'ecran, j'ai un un message (cf screen):
"Windows 7
numéro 7600
cette copie de windows n'est pas authentique"

Pourtant j'ai bien acheter mon ordinateur avec cette version de windows (je ne l'ai pas cracké).

comment puis-je résoudre mon probleme ?

3 réponses

  1. jmber Messages postés 2067 Date d'inscription   Statut Contributeur Dernière intervention   680
     
    Bonsoir,

    Peux-tu faire un scan avec HijackThis et poster le rapport, si tu n'as pas le programme, tu peux le télécharger ICI
    0
  2. Utilisateur anonyme
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:32:49, on 22/12/2010
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Unable to get Internet Explorer version!
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Steam\Steam.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Mes documents\Telecharger\HiJackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
    0
    1. jmber Messages postés 2067 Date d'inscription   Statut Contributeur Dernière intervention   680
       
      Relances Hijack et "Fix" ces lignes ==>

      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

      Après, tu télécharges et executes MalxwareByte's AntiMalware ==> le programme est ICI
      Passe un scan complet et poste le rapport
      0
    2. Utilisateur anonyme
       
      Malwarebytes' Anti-Malware 1.50
      www.malwarebytes.org

      Version de la base de données: 5379

      Windows 6.1.7600
      Internet Explorer 8.0.7600.16385

      23/12/2010 11:27:03
      mbam-log-2010-12-23 (11-27-03).txt

      Type d'examen: Examen complet (C:\|D:\|)
      Elément(s) analysé(s): 279064
      Temps écoulé: 54 minute(s), 58 seconde(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 5
      Fichier(s) infecté(s): 7

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      c:\program files\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
      c:\program files\Hotbar\bin (Adware.Hotbar) -> Quarantined and deleted successfully.
      c:\program files\Hotbar\bin\11.0.175.0 (Adware.Hotbar) -> Quarantined and deleted successfully.
      c:\program files\Hotbar\bin\11.0.175.0\firefox (Adware.Hotbar) -> Quarantined and deleted successfully.
      c:\program files\Hotbar\bin\11.0.175.0\firefox\extensions (Adware.Hotbar) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      c:\Users\pierre alain\downloads\install_vlc_clic.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
      c:\$RECYCLE.BIN\s-1-5-21-4103661892-938371717-2238623320-1000\$RB362JI.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
      c:\mes documents\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
      c:\mes documents\downloads\sony vegas pro v9.0b build 772-digital insanity[h33t][frapmat212]\Keygen.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
      c:\mes documents\telecharger\vdownloader1.12_setup.exe (Adware.ADON) -> Quarantined and deleted successfully.
      c:\program files\Hotbar\bin\11.0.175.0\copyright.txt (Adware.Hotbar) -> Quarantined and deleted successfully.
      c:\program files\Hotbar\bin\11.0.175.0\firefox\extensions\install.rdf (Adware.Hotbar) -> Quarantined and deleted successfully.
      0
  3. kaneagle Messages postés 86295 Date d'inscription   Statut Modérateur Dernière intervention   14 686
     
    Bonsoir,

    Merci de lire ceci:

    --> Activer Windows
    --> Légaliser Windows
    -1
    1. Utilisateur anonyme
       
      Ma version est légale et activée....
      0
    2. jmber Messages postés 2067 Date d'inscription   Statut Contributeur Dernière intervention   680
       
      Téléchargez la dernière version de ZHPDiag ==> ZHPDiag
      Enregistrez le sur votre Bureau.
      Une fois le téléchargement achevé, faites un double clic sur ZHPDiag.exe et suivez les instructions.
      N'oubliez pas de cocher la case qui permet de mettre un raccourci sur le Bureau.
      pour Xp :Double cliquez sur le raccourci ZHPDiag du Bureau.
      pour vista et Seven : faites un clic droit sur le raccourci ZHPDiag du Bureau et choisissez "exécuter en tant qu'administrateur".

      Cliquez sur la loupe pour lancer l'analyse.
      A la fin de l'analyse, fermer ZHPDiag. Il a créé un rapport automatiquement qu'il va falloir poster.
      Suivez ces instructions :

      Cliquez sur Cijoint ou Cjoint
      Cliquez sur Parcourir et cherchez le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).
      Sélectionnez le fichier ZHPDiag.txt.
      Un peu plus bas, cliquez sur "Cliquez ici pour déposer le fichier".
      Un lien de cette forme ==> http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt est ajouté dans la page.
      Copiez ce lien et postez-le.
      0
    3. Utilisateur anonyme
       
      Voici, comme demandé : http://www.cijoint.fr/cjlink.php?file=cj201012/cij0O6j8NU.txt
      0
    4. jmber Messages postés 2067 Date d'inscription   Statut Contributeur Dernière intervention   680
       
      Apparemmment, pas de soucis mais une verif supplémentaire ne fait pas de mal,

      Télécharger AD-Remover ==> ICI
      Double-clique sur le fichier téléchargé AD-R.exe
      (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
      Au menu principal, choisis l'option Nettoyer.
      Poste le rapport généré ( C:\Ad-Report-Scan-(date).log ).

      ( CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

      Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      0
    5. Utilisateur anonyme
       
      Le programme ne fonctionne pas. Il ouvre une boite de dialogue noir, et plus rien...

      Autre : Est-il possible de bloqué un scan disque à chaque redémarrage de windows (sous W7) ? C'est le seul probleme qui persiste à présent.
      0