Problemes de virus meme apres un scan spybot

Résolu
grecoriz Messages postés 49 Date d'inscription   Statut Membre -  
 chouchou -
Bonjour,

J'ai essayé de faire une recherche sur le site mais la page de recherche est indisponible.

Alors voila, j'ai essayé de résoudre mon problème avec spybot mais apparemment, il en reste encore; donc, j'ai essayé avec hijack et voila la log qui en résulte.

je n'i pas eu le temps de lire la notice mais promis, je vais le faire.

Cdt.

le grec

Logfile of HijackThis v1.99.1
Scan saved at 14:56:57, on 10/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\apinc32.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\javauu.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\ClamWin\bin\OlAddin.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\EditPlus 2\editplus.exe
E:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {4873121D-827E-1BD4-1A2C-B5A0C13C9785} - C:\WINDOWS\system32\ievy.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Class - {6D58C8C3-0A00-0929-E359-77C521C2D819} - C:\WINDOWS\ntdz32.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Class - {AF2504CE-9FD2-4BFE-D073-D844B4100716} - C:\WINDOWS\atlcx.dll
O2 - BHO: Class - {C966F763-7FFA-9FA1-5FC7-B5934547E742} - C:\WINDOWS\system32\crbh.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [apinc32.exe] C:\WINDOWS\apinc32.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OpenOffice.org 1.1.3.lnk.disabled
O4 - Global Startup: Acrobat Assistant.lnk.disabled
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{099CA906-45C0-4634-B635-04DCF80D45D0}: NameServer =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\..\{099CA906-45C0-4634-B635-04DCF80D45D0}: NameServer =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\javauu.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe

12 réponses

  1. Utilisateur anonyme
     
    salut commence par desactivé ce service

    dans le Menu Démarrer/Panneau de Configuration/Outils d'administration/Services
    Dans la fenêtre qui s'ouvre, double-clique sur la ligne "Workstation NetLogon Service ".
    Dans le champ "Type de démarrage" de l'onglet "Général", sélectionne "Desactivé".
    Clique sur "Arrêter".
    Clique ensuite sur "OK" pour valider la configuration.

    ferme toute les fenetre et programe /lance hijack/coche ces lignes et clike sur fix checked

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\zsibo.dll/sp.html#10001%resultposition.net
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - Default URLSearchHook is missing

    O2 - BHO: Class - {4873121D-827E-1BD4-1A2C-B5A0C13C9785} - C:\WINDOWS\system32\ievy.dll
    O2 - BHO: Class - {6D58C8C3-0A00-0929-E359-77C521C2D819} - C:\WINDOWS\ntdz32.dll
    O2 - BHO: Class - {AF2504CE-9FD2-4BFE-D073-D844B4100716} - C:\WINDOWS\atlcx.dll
    O2 - BHO: Class - {C966F763-7FFA-9FA1-5FC7-B5934547E742} - C:\WINDOWS\system32\crbh.dll

    O4 - HKLM\..\Run: [apinc32.exe] C:\WINDOWS\apinc32.exe

    1.redemarre en mode sans echec (redemarage + tapotte sans arret sur F8 desque l'ordi s'allume)

    2. desactive ta restauration (pour win xp ) comme ceci :
    clike droit sur post de travaille/proprietes/restauration system et la tu coche desactiver la restauration du systeme tu applique

    3. affiche les fichier cacher comme ceci :
    clicker sur demarrer/panneau de configuration/option des dossiers/affichage
    Cocher afficher les dossiers cacher
    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
    Puis fais «Ok» pour valider les changements.
    Decocher masquer les extentions dont le type est connues

    4.ensuite va dans demarrer/rechercher et tape:
    ievy.dll
    ntdz32.dll
    atlcx.dll
    crbh.dll
    apinc32.exe

    suprime les et vide ta corebeille

    reactive la restauration et masque les fichiers caché en suivant le meme chemin

    redemare en mode normal :

    elecharge et execute ces antispywares ( pense a les mettre a jour avant de les lancées)
    (1) ad-aware version 1.06

    (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
    voir demo
    http://pageperso.aol.fr/balltrap34/adwseflash.zip
    ***
    (2) spybot version 1.4

    (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite

    voir demo d utilisation
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
    ***
    (4) a2

    http://www.emsisoft.net/fr/
    penser a le metre a jour avant de scanner le pc
    ***
    ps : un grand merci a balltrap pour les lien :)

    (5) Edwido
    http://download.ewido.net/ewido-setup.exe
    Pendant l'installation, sur la page "Additional Options", décoche les deux options "Install background guard" et "Install scan via context menu Ewido Security Suite. Clique sur mise à jour.

    Clique sur scanner puis sur scan complet du système.

    installe un antivirus

    (avast)
    http://www.clubic.com/telecharger-fiche11113-avast-.html
    (tuto avast)
    http://www.pcentraide.com/index.php?showtopic=120

    installe un firewall je te conseille

    (kerio)
    http://www.clubic.com/telecharger-fiche11071-kerio-personal-firewall.html

    (tutorial kerio) :
    http://www.pcentraide.com/index.php?showtopic=110

    refait un scan et colle le resultat ici
    @++++++++
    0
    1. grecoriz Messages postés 49 Date d'inscription   Statut Membre 5
       
      Merci, apparemment, ca a l'air de bien fonctionner...
      Par contre ... euhh ... comment dire

      En fait, j'ai installer avast sur mon poste (un autre), et depuis, au démarrage, il rame pendant un (tres tres) long moment puis se bloque . Une fois, il m'a meme dis que je n'avais pas les autorisations pour éteindre ma machine!

      Donc voila, je suis obliger de démarrer en mode sans échec pour pouvoir accéder au web...

      Du coup j'installe agnitum outpost firewall et je fais un scan hijack et je vous transmet la log.


      Logfile of HijackThis v1.99.1
      Scan saved at 07:20:09, on 11/01/2006
      Platform: Windows 2000 (WinNT 5.00.2195)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINNT\System32\smss.exe
      C:\WINNT\system32\winlogon.exe
      C:\WINNT\system32\services.exe
      C:\WINNT\system32\lsass.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\System32\WBEM\WinMgmt.exe
      C:\WINNT\Explorer.exe
      C:\Documents and Settings\greg\Bureau\hijack\HijackThis.exe
      C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      F2 - REG:system.ini: UserInit="main6.exe" - -
      O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINNT\nem220.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
      O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
      O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
      O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk\PDesk.exe /Autolaunch
      O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
      O4 - HKLM\..\Run: [Winamp Agent] C:\WINNT\System32\winamp.exe
      O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINNT\System32\csrs.exe
      O4 - HKLM\..\Run: [ntdll.dll] C:\WINNT\System32\spooIsv.exe
      O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
      O4 - HKLM\..\Run: [Spooler SubSystem App] C:\WINNT\System32\spooIsv.exe
      O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
      O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
      O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
      O4 - HKLM\..\Run: [\TNN] C:\windows\mrjj.exe
      O4 - HKLM\..\Run: [taskbar.exe] C:\dm.exe
      O4 - HKLM\..\Run: [virD] C:\windows\mrjj.exe
      O4 - HKLM\..\Run: [enewsletterpro] c:\windows\enewsletterpro.exe
      O4 - HKLM\..\Run: [banmanpro] C:\windows\banmanpro.exe
      O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
      O4 - HKCU\..\Run: [internat.exe] internat.exe
      O4 - Startup: WinMySQLadmin.lnk = D:\mysql\mysql\bin\winmysqladmin.exe
      O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
      O9 - Extra button: Réglage rapide de Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
      O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\dHJlbXJhbg\command.exe (file missing)
      O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
      O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe
      O23 - Service: MySql - Unknown owner - D:/mysql/mysql/bin/mysqld-nt.exe
      O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
      O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

      MERCI d'avance
      0
  2. Utilisateur anonyme
     
    salut je comprend pourquoi avast plante t'es trop infecté

    fix ceci avec hijack

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINNT\nem220.dll

    O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINNT\System32\csrs.exe
    O4 - HKLM\..\Run: [ntdll.dll] C:\WINNT\System32\spooIsv.exe
    O4 - HKLM\..\Run: [Spooler SubSystem App] C:\WINNT\System32\spooIsv.exe
    O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
    O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
    O4 - HKLM\..\Run: [\TNN] C:\windows\mrjj.exe
    O4 - HKLM\..\Run: [taskbar.exe] C:\dm.exe
    O4 - HKLM\..\Run: [virD] C:\windows\mrjj.exe
    O4 - HKLM\..\Run: [enewsletterpro] c:\windows\enewsletterpro.exe
    O4 - HKLM\..\Run: [banmanpro] C:\windows\banmanpro.exe
    O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe

    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\dHJlbXJhbg\command.exe (file missing)

    1.redemarre en mode sans echec (redemarage + tapotte sans arret sur F8 desque l'ordi s'allume)

    2. desactive ta restauration (pour win xp ) comme ceci :
    clike droit sur post de travaille/proprietes/restauration system et la tu coche desactiver la restauration du systeme tu applique

    3. affiche les fichier cacher comme ceci :
    clicker sur demarrer/panneau de configuration/option des dossiers/affichage
    Cocher afficher les dossiers cacher
    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
    Puis fais «Ok» pour valider les changements.
    Decocher masquer les extentions dont le type est connues

    4.ensuite va dans demarrer/rechercher et tape: fait tres attention dans l'orthographe des fichier

    csrs.exe
    spooIsv.exe ( ne pas confondre avec spoolsv.exe qui est un fichier system)
    scvhost.exe ( ne pas confondre avec svchost.exe qui est un fichier system)
    drsmartloadb.exe
    mrjj.exe
    dm.exe
    enewsletterpro.exe
    banmanpro.exe

    suprime les et vide ta corebeille

    reactive la restauration et masque les fichiers caché en suivant le meme chemin

    redemare en mode normale

    execute les antispywares et installe avast

    j'ai un doute sur cette ligne

    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe

    donc va sur ce site :
    http://www.virustotal.com/xhtml/virustotal_en.html
    Clik sur parcourir
    Recherche ce qui est en gras :

    C:\Program Files\Network Monitor\netmon.exe

    Clik send et colle le rapport ici

    @+++++++
    0
  3. grecoriz Messages postés 49 Date d'inscription   Statut Membre 5
     
    ouais j'ai fait et meme refait, mais il y a dm.exe qui se lance quand meme au démarrage de mon poste.

    Ce que j'ai fait:
    démarrage en mode sans échec
    fixage avec HJT
    redémarrage en mode sans échec
    suppression des fichiers
    vidage de corbeille
    spybot & ad-aware
    et au redémarrage en mode normal pour télécharger et installer avast le dm.exe se lance...

    snif!

    Bon je réessaye ce soir et vous tiens au courant.
    0
  4. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    bjr
    chouette
    un bon client , bien pourri
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    salut le fix avec hijack doit se faire en mode normal

    refait un hijack et colle le resultat ici
    @++++++++
    0
  7. grecoriz Messages postés 49 Date d'inscription   Statut Membre 5
     
    Super maintenant ca fonctionne du feu de dieu...
    Finalement, comme en mode normal ca ne démarrait toujours pas, j'ai :
    fixé tout ceux que l'on m'a signalé en mode sans échec
    supprimé les fichiers temporaires en faisant une recherche sur le
    disque
    vidé ma corbeille
    lancer les antispywares
    installer avast en demandant une analyse au démarrage

    Au démarrage avast m'a trouvé une quinzaine de fichiers infectés.

    J'ai aussi installé outpost en firewall et depuis tout va bien.

    Je mets quand mm mon dernier post Hijack ... juste au cas ou

    Logfile of HijackThis v1.99.1
    Scan saved at 06:56:30, on 15/01/2006
    Platform: Windows 2000 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\hidserv.exe
    C:\WINNT\System32\mgabg.exe
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    D:\mysql\mysql\bin\mysqld-nt.exe
    C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\System32\inetsrv\inetinfo.exe
    C:\WINNT\Explorer.exe
    C:\WINNT\System32\msucom.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINNT\loadqm.exe
    C:\Program Files\Google\Google Talk\googletalk.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Documents and Settings\greg\Bureau\hijack\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
    O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
    O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINNT\System32\firewall.exe
    O4 - HKLM\..\Run: [objupdate] C:\WINNT\System32\msucom.exe
    O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\System32\logon.exe
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Startup: WinMySQLadmin.lnk.disabled
    O4 - Global Startup: Service Manager.lnk.disabled
    O9 - Extra button: Réglage rapide de Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe
    O23 - Service: MySql - Unknown owner - D:/mysql/mysql/bin/mysqld-nt.exe
    O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    Et merci pour tout
    0
  8. jpdeclermont Messages postés 1792 Statut Membre 382
     
    bonjour,

    ouais ben c'est pas fini mon gars :)
    y a encore plein de cochonneries

    -------------------------------
    ... WinErr 01B : Erreur illégale - Windows ne vous a pas autorisé à avoir cette erreur
    0
  9. plazanet
     
    je dessire installer le logiciel spybot-search et destroy pour les virus merci de bien vouloir m'aider Mm plazanet
    0
    1. jpdeclermont Messages postés 1792 Statut Membre 382
       
      bonjour,

      merci de créer ton propre message, sinon la lecture devient extrèmement pénible
      va voir plutot dans la section windows, si c'est juste une question d'installation, j'arrive ....


      -------------------------------
      ... WinErr 01B : Erreur illégale - Windows ne vous a pas autorisé à avoir cette erreur
      0
    2. Utilisateur anonyme
       
      salut plazanet tu trouvera le lien pour telecharger spybot dans mon message numero 1
      je precise que spybot n'est pas un antivirus mais un antispyware

      pour les virus vaut mieu installé avast

      @+++++++
      0
  10. Utilisateur anonyme
     
    salut il reste encore des saleté mais c'est beaucoup mieu que le premier scan

    fix ceci avec hijack en mode normal

    O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINNT\System32\firewall.exe
    O4 - HKLM\..\Run: [objupdate] C:\WINNT\System32\msucom.exe
    O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\System32\logon.exe
    O4 - Global Startup: Service Manager.lnk.disabled

    puis redemare en mode sans echec +resto desactiver+ fichier caché affiché

    cherche et supprime

    firewall.exe
    msucom.exe
    logon.exe (ne pas confondre avec winlogon qui est un fichier system)

    sinon je vois que ton windows n'est pas ajour donc pour plus de protection va faire un tour chez windows update ;-)

    @+++++++
    0
    1. jpdeclermont Messages postés 1792 Statut Membre 382
       
      re-

      salut jess :))
      la routine ce matin .....

      -------------------------------
      ... WinErr 01B : Erreur illégale - Windows ne vous a pas autorisé à avoir cette erreur
      0
  11. grecoriz Messages postés 49 Date d'inscription   Statut Membre 5
     
    Cool ca marche,

    J'ai mis à jour mon ordi et le maintient a jour avec windows update.

    Et encore un grand merci.

    Cdt
    0
  12. chouchou
     
    Bonjour,
    slt j'ai un probléme avec mon pc on ma envoyer un merusse msn qui se nom n039 comment je peur m'en débarraser et moi j'ai avast anti verus merci de votre réponse
    0