[ virus ou trojant] Besoin d'aide

Aurelieeee Messages postés 64 Statut Membre -  
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour , j'ai besoin d'aide s'il vous plait

Depuis peu mon anti virus détecte assez souvent des virus ou troyen.. avec beaucoup de mal j'ai réussi il me semblait a m'en dépêtré mais je ne pense pas que la menace soit totalement éradiqué.

A explorant le forum afin d'avacancer le travail J'ai pu voir que vous fonctionné beaucoup avec HijackThis J'ai donc fait un scan en voici le rapport.
Je join un rapport d'ewido ainsi qu'un scan avec Bit defendre Online fin de complété un eventuel manque d'information.

Je suis prête et disponible a recevoir toutes aides pouvant m'aider.

Merci d'avoir pris quelque minute pour avoir lu ce post et je l'espère recevoir un peu d'aide.

@ bientôt

Logfile of HijackThis v1.99.1
Scan saved at 11:08:58, on 07/11/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\System32\services.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\TEMP\winBC76.tmp
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\nou\LOCALS~1\Temp\Rar$EX00.907\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = LanguedocWarez Rien que pour le plaisir!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\loader8108921.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll (file missing)
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\System32\msasvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 14:38:32 07/11/2006

+ Scan result:

C:\mjbvlado.exe -> Backdoor.Pakes : No action taken.
C:\Documents and Settings\nou\Local Settings\Temp\2.dlb -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\nou\Local Settings\Temp\6.dlb -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\nou\Local Settings\Temp\7.dlb -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\nou\Local Settings\Temp\Temporary Internet Files\Content.IE5\WD2FKPUR\loader[1].exe -> Downloader.Tiny.bm : No action taken.
[1184] C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll -> Proxy.Xorpix.at : No action taken.
C:\Documents and Settings\nou\Cookies\nou@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\nou\Cookies\nou@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\nou\Cookies\nou@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\nou\Cookies\nou@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\nou\Cookies\nou@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\nou\Cookies\nou@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\nou\Cookies\nou@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\nou\Cookies\nou@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\nou\Cookies\nou@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\nou\Cookies\nou@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\nou\Cookies\nou@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\nou\Cookies\nou@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\WINDOWS\system32\msasvc.exe -> Trojan.Sinowal.bh : No action taken.
[964] C:\WINDOWS\System32\msasvc.exe -> Trojan.Sinowal.bh : No action taken.

::Report end

______________________________________________________

BitDefender Online Scanner

Scan report generated at: Tue, Nov 07, 2006 - 12:50:18

Scan path: A:\;C:\;D:\;E:\;

Statistics

Time
01:13:47

Files
131743

Folders
2871

Boot Sectors
2

Archives
2302

Packed Files
8794

Results

Identified Viruses
4

Infected Files
5

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
5

Engines Info

Virus Definitions
312708

Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)

Scan plugins
13

Archive plugins
38

Unpack plugins
6

E-mail plugins
6

System plugins
1

Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions

Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes

Scanned File
Status

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP18\A0002648.exe=>(NSIS o)=>zlib_nsis0002
Infected with: Trojan.Dropper.VB

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP18\A0002648.exe=>(NSIS o)=>zlib_nsis0002
Disinfection failed

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP18\A0002648.exe=>(NSIS o)=>zlib_nsis0002
Deleted

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP18\A0002648.exe=>(NSIS o)
Update failed

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022921.exe
Infected with: Trojan.Downloader.Small.CPT

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022921.exe
Deleted

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022991.dll
Infected with: Generic.Malware.SMdldg.D37C9328

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022991.dll
Disinfection failed

C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022991.dll
Deleted

C:\WINDOWS\msagent\agentsvr.exe
Infected with: Win32.Mixor.A@mm

C:\WINDOWS\msagent\agentsvr.exe
Disinfection failed

C:\WINDOWS\msagent\agentsvr.exe
Deleted

C:\WINDOWS\system32\dllcache\agentsvr.exe
Infected with: Win32.Mixor.A@mm

C:\WINDOWS\system32\dllcache\agentsvr.exe
Disinfection failed

C:\WINDOWS\system32\dllcache\agentsvr.exe
Deleted

voila voila :/
UNe question aussi, les fichiers placé en quarentaire par ewido doivent-ils etre suprimé ?
A voir également:

38 réponses

Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Re,

Tu peux resumer brievement tes soucis?

a+
0
Aurelieeee Messages postés 64 Statut Membre 4
 
Mon pc plante anormalement très souvent, son utilisation re devien un calvaire

_L'écran se fige la souris ne bouge pu
_ aucune manip ne répond*
( meme en tapotan sur la touche Ver Maj ou Ver num les lumière du clavier devan m'indiqué l'utilisation de tel ou tel touche ne réagisse pu...)
_ le son se coupe aussi

TOUT est planté

Je dois pour cela reté appuyé longuement sur le bouton pour allumé le pc pour l'arrété.
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Re

Desactive ton pare feu, c est pareil?

A+
0
Aurelieeee Messages postés 64 Statut Membre 4
 
pour jouer en reseaux je desactive toujours mon par feu et il se bloque au bout de 2 minute en jouant..

En surfant ou en fesant du traiement de texte ou autre occupation banale cela arrive aussi mais moin rapidement

0
Aurelieeee Messages postés 64 Statut Membre 4
 
J'ai quand meme desactivé le parfeu mais le pc viens de planté..
0
Aurelieeee Messages postés 64 Statut Membre 4
 
Bonjour,

Je fais le point sur ma situation une nouvelle fois:

Après avoir été fortement contaminé par des trojans et autre bestioles que je pensais avoir totalement éradiqué..

Mon pc plante constament, c'est à dire: en jouant en reseaux le pc fonctionne parfois 2 minutes parfois 10minutes mais ce n'est en aucun cas jouable a chaque fois.
En surfant ou en fesant du traitement de texte ou autre.. Meme chose le pc plante
A chaque fois l'image se fige, la souris ne bouge pu,le son se coupe, aucune manipulation ne répond.. meme les lumière du clavier devant en principe s'allumé en appyant sur Ver Num ou Ver Maj ne répondent pu..(celà reste un détail c'est pour mieux vous informé du degré de "plantage")
La seule chose a faire est de resté longuement appuyé sur le bouton d'alimentation de la tour pour quelle s'eteigne et redémarre pour me refaire la meme chose.
_____________________________________________


Ce que j'ai fait jusqu'à maintenant:


- Scaner avec Ewido: il me trouve que des cookies avec indice de danger "Medium" que je supprime directement
- Scaner avec Spybot: idem qu'Ewido
- Scaner avec Ad-Aware: idem qu'Ewido & Spybot
- Scaner avec mon anti virus AVast: il ne trouve rien
- Scaner avec Kaspersky online: il m'as trouvé une bonne dizaine de trojant
- nettoyer mon registre avec Regseeker
- Fait un nettoyage ave Ccleaner
- J'ai Ouvert mon pc je les passé a la souflette pour eliminé les poussières
- Controlé les ventilateurs

Ensuite donc j'ai télécharger Kaspersky(version d'essai 30 jours) j'ai scané mon pc il a su me virer tout un tas de betioles: Trojan, Cookies..
j'ai re-scané par la suite pour etre sûr! R.A.S aparrament je serais Clean
J'ai rescané en ligne mais cette fois avec Bitdefender Online: il m'as trouvé les trojant placé dans le backup de Kaspersky, J'ai supprimé toutes trace de ces trojants.

Je vous poste un log de HiJakthis en bas de ce poste pour d'eventuelles informations qui vous serez utiles.

Cependant après toutes ces manipulations très longues, mon problème reste inchangé: le pc se bloque aussi rapidement qu'avant en jouant en reseaux et comme auparavant au bout de 1 ou 2 heures parfois 10minutes en ne fesant rien de spécial.

Je ne sais plus quoi faire.. ces problème étaient résolue après ma dernière grosse contamination mais bon le plaisir n'as pas duré plus de 2 semaine.

Je reste a disposition pour toute aide ou manipulation pouvant m'aider a résoudre ce problèmes.

Merci d'avoir pris quelques minutes en ayant lue ce post.
@ bientot
______________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 15:48, on 06-11-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = LanguedocWarez Rien que pour le plaisir!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?72fd761c7ed84d648356d8a18f264629
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?72fd761c7ed84d648356d8a18f264629
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
0
Utilisateur anonyme > Aurelieeee Messages postés 64 Statut Membre
 
Tu as trop de gens..
0
Aurelieeee Messages postés 64 Statut Membre 4 > Aurelieeee Messages postés 64 Statut Membre
 
J'ai pas compris l'sens de ta phrase..
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Salut,

Scaner avec Kaspersky online: il m'as trouvé une bonne dizaine de trojant 


On peut avoir le rapport?

A+
0
Aurelieeee Messages postés 64 Statut Membre 4
 
Salut,

J'ai donc télécharger kaspersky après ce scan, il m'as trouvé autant de trojan, que j'ai réussi a supprimé. Mais je doute que mes soucis soit réglé, le pc plante encore très souvent.

@+

KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 14, 2006 3:14:11 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 14/11/2006
Kaspersky Anti-Virus database records: 227474
Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 57033
Number of viruses found 8
Number of infected objects 12 / 0
Number of suspicious objects 0
Duration of the scan process 00:39:10

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\cert8.db Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\history.dat Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\key3.db Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\parent.lock Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\search.sqlite Object is locked skipped
C:\Documents and Settings\nou\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\nou\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Application Data\Mozilla\Firefox\Profiles\zd2m8lm2.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Historique\History.IE5\MSHist012006111420061115\index.dat Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\leftTopMenu[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\liensCommRight-title[1].png Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\log[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\membre[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\mymsn[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\onglet_info_off[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\optn=1[1] Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\show23[1].asp Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\smartad[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\smiley[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\start[2].css Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\tab.separator.on.l[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\tld2bg[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\WMCLogo[1].png Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\wreport[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\X_barre_acc[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\ALBKDGBM\zsa_hp_04[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\3x_ssfrais_ok_03[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\403307094_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\403310641_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\519108445_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\bannerFR1[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\BC19119EE793ABA0722E932110B283[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\bg3[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\DartRichMedia_1_03[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\desktop.ini Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\d[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\entreprise-1[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\expand_~Right~_rest_~ContainerHeaderTextLuminance~[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\flag_croatia[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\Home[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\HTML[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\i.p.emwink[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\ie60win[2].css Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\ImageClicable5[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\imprimer[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\includenbcomment[4].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\includenbcomment[7].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\jewel_collage[1].png Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\Live.Controls.CustomizeDialog[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\look2_1[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\micro[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\msft[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\nav2_r[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\offres_haut_gauxhe[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\onglet_jouets_off[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\open[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\referencez-le[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\relance_05[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\remotesuggestions[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\remote[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\satisfait1[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\show23[4].asp Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\signup[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\SMmega_lancement1[1].swf Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\souvenir[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\CPIN4T2N\tiretsrouge_305_bordgauchedroite[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\bracelet_offert[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\CAZISNR1.htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\cothaut_garantie[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\desktop.ini Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\gateway[1].31418 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\gateway[1].5226 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\global[3].css Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\grattage[4].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\hl2[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\img[2].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\info[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\page-prix-fou_02[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\FZ17BPKW\skyblogsms[1].png Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\25169_90_70_FFFFFF[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\2586[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\3009ab322882[1] Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\41B26545CBDCCFE86C61FB6A52EC3[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\601187146_comment_1[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\audible_a_icon_15T[1].png Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\desktop.ini Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\ecrire[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\env[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\gateway[1].5864 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\gateway[1].9263 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\getmsg_urlframewarn[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\i.p.im_off[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\mari0n-59.spaces.live[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\KPQF0TU3\msft[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\535564119_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\601174470[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\alaune-071106[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\bouton[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\grand_jeu[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\hawaii_blue0102_S_Informations_944A882C_FR[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[10].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[15].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[21].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[26].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[33].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[4].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\search[6].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\M7ABAH6F\select_all[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\471562233[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\473799729_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\AO%3D0%3BLY%3D0%3BYA%3D0%3BGO%3D0%3BRSS%3D0%3BCA%3D0%3Bbillboard%2CSousRubrique%2Cwindows_Bureautique_tableur[1] Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\Ban_v4_DernieresNews[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\b_new[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\dragdrop[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\OXOLAF8T\HeaderCenterImage[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Q93QJ7C0\42239_90_70_FFFFFF[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Q93QJ7C0\btn_hot_normal[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Q93QJ7C0\gateway[1].15600 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Q93QJ7C0\gateway[1].20448 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\495139122_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\bl_rs[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\btn_jouer[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\CAFIUTNJ.htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\grattage[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\grattage[6].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\tagger_v02[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\SXQZS5UR\TC_produit_points_promo[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\1011-video-ina[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\1531885604@Top,Bottom[2] Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\1564320968@Top,Bottom[1] Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\abonne[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\clearicon_~ContainerHeaderTextLuminance~[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\commentaireForm[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\cr[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\ebayfooter_e4831fr[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\fl_t_bg_1[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\FutureCREW-paveSupv2[1].swf Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\gateway[1].16573 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\gateway[1].17572 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\gateway[1].25947 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\gateway[1].30635 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\gateway[1].7614 Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\global[3].css Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\grattage[7].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\header[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\helppane___10210002F[2].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\W9YZ8L27\spacer[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\343245173_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\495174216_small[1].jpg Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\511918626_comment_1[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\builder[1].js Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\CA5WONH1.swf Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\CAFMAD77.htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\campaign_postxmas_2_234x60[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\CAT8YH9F.htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\logo[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\menuitem_fr_pe_2[1].xml Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\monde0[1].css Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\start[1].cab Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\success[1].htm Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\tr_vsure[1].gif Object is locked skipped
C:\Documents and Settings\nou\Local Settings\Temporary Internet Files\Content.IE5\Y18R6DQ5\VerticalBleu_DA28EF6_FR[1].jpg Object is locked skipped
C:\Documents and Settings\nou\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\nou\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped
C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022889.exe Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022890.exe Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022891.exe Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022892.exe Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022919.exe Infected: Trojan-Downloader.Win32.Small.dzd skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022920.exe Infected: Trojan-Proxy.Win32.Xorpix.au skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022922.exe Infected: Email-Worm.Win32.Glowa.g skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP86\A0022923.exe Infected: Trojan-Downloader.Win32.Tibs.jb skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP87\A0024158.exe Infected: Trojan-Downloader.Win32.Tiny.bw skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP87\A0024159.exe Infected: Backdoor.Win32.Pakes skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP90\A0027631.exe Infected: Trojan.Win32.Agent.zq skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP94\A0039258.exe Infected: Trojan-Downloader.Win32.Tibs.jb skipped
C:\System Volume Information\_restore{EE5C1D49-E816-48D3-9EEF-82DEDEB6497C}\RP99\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_48c.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Salut,

Tu as 2 antivirus?

A+
0
Aurelieeee Messages postés 64 Statut Membre 4
 
salut,

J'ai installé Kaspersky pour virer les trojan que avast ne voyé pas, je comptais garder kaspersky juska la fin de sa versoin d'essai au cas où, avast est desactivé jusqu'a cette date. celà pose t-il problème ?

Encor est toujours en train de planté sinon..

@ bientot
0
Aurelieeee Messages postés 64 Statut Membre 4
 
Salut,

pour en finir J'ai gardé Kaspersky j'ai enlevé totalement Avast & Kerio étant donné que kaspersky possède déjà un ParFeu..

Je reste a disposition, a bientot
0
^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 279
 
Slt

Peux tu faire un récapitulatif de tes soucis
stp

A++
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Salut

Oui, tu ne dois avoir qu un seul antivirus et un seul pare feu !

a+
0
Aurelieeee Messages postés 64 Statut Membre 4
 
le probleme c'est que mon pc plante tout le temps: l'écran se fige pu rien n'est possible, aucune manip

obligé de reboot..
0
^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 279
 
Slt

Peux tu faire un Hitjackthis
stp

0
Aurelieeee Messages postés 64 Statut Membre 4
 
voila en esperant que ceci pour t'aider.
Merci a bientot.

_________________________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 16:50, on 06-11-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HLSW\hlsw.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = LanguedocWarez Rien que pour le plaisir!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?72fd761c7ed84d648356d8a18f264629
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?72fd761c7ed84d648356d8a18f264629
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
0
Aurelieeee Messages postés 64 Statut Membre 4
 
hm !!!!!
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Salut

En fait ton pc se fige c est ca?

A+
0
Aurelieeee Messages postés 64 Statut Membre 4
 
remonter un peu plus haut dans la discussion pourrait permettre de perdre beaucoup moins de temps. a chaque fois on me demande ce que mon pc as..

Mon pc se fige, oui
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Re,

Panneau de Configuration > Système > onglet Avancé > § Performances [Paramètres] >
onglet Avancé > § Mémoire virtuelle [Modifier] ==> on obtiens cette fenêtre < http://img225.imageshack.us/img225/9274/screenshot148rx9.gif > mettre C: en surbrillance.
( au bas, on lit "recommandée = 766 Mo" ; ce n'est pas suffisant, et ça ralenti la machine ! )
Il faut donc, par exemple, taper 1000 Mo ( taille minimale = initiale ) et 2500 ( maximale ); si tu as déjà un maximal de 2500, augmente par exemple à 3000 Mo.
NB: La VM représente une augmentation de la mémoire virtuelle qui risquerait d'être saturée.
0
Aurelieeee Messages postés 64 Statut Membre 4
 
c'est fait, merci je te tiens au courant.

Bonne apremidi
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
ok merci

a+
0
yoyo
 
bonjour je crois que j'ai un virus alors je vient poster mon rapport hijackthis, quelqu'un pourrait-il me dire si je suis infecté et si oui comment nettoyer l'ordi merci d'avance.

Logfile of HijackThis v1.99.1
Scan saved at 10:28:58, on 14/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\e-Carte Bleue\CL\e-Carte Bleue VISA Cleo\ECB-CLEO.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\windows\system32\lpdsrngs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: adssite - {F31B3634-12AA-41ca-B021-0685C3B3E4CA} - C:\WINDOWS\system32\nsxA6.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [eCarteBleue-CLEO] "C:\Program Files\e-Carte Bleue\CL\e-Carte Bleue VISA Cleo\ECB-CLEO.exe" /dontopenmycards
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [hpfsched] C:\WINDOWS\hpfsched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqmdt.exe P2D002
O4 - HKLM\..\Run: [{95-5A-AC-C8-ZN}] C:\windows\system32\lpdsrngs.exe P2D002
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lpdsrngs.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwinqmdt.exe
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: https://www.orpi.com/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{02EE8895-8F1F-4692-A0BB-35465579E640}: NameServer = 192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{02EE8895-8F1F-4692-A0BB-35465579E640}: NameServer = 192.168.0.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
0
Regis59 Messages postés 21143 Date d'inscription   Statut Contributeur sécurité Dernière intervention   1 322
 
Bonjour,

Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
Procèdes comme ceci :
http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm

A bientôt
0