Desinfection impossible, ordi tres lent !!! - Page 2

Précédent
  • 1
  • 2
  1. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Re,

    Il est là : C:\\\_OTMoveIt\MovedFiles

    FillPCA
    0
  2. piloterepdom
     
    voila,

    y a t il une amelioration dans mon systeme ...........

    File/Folder C:\WINDOWS\jetctrl.dll not found.
    C:\WINDOWS\vipextmdx.dll unregistered successfully.
    C:\WINDOWS\vipextmdx.dll moved successfully.

    Created on 12-18-2007 21:18:20
    0
  3. piloterepdom
     
    y a t il du nouveau apres ce nettoyage .....merci
    0
  4. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Re,

    Oui.

    1/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download

    Ouvre Ccleaner, clique sur "lancer le nettoyage".

    2/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
    Tu l'installes.
    Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.

    Clique sur le bouton Analyse (de la barre d'outils)
    Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
    Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
    A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
    Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

    3/ * Fais un scan en ligne en cliquant ici : http://assiste.com.free.fr/...
    * Choisis Kaspersky.
    * Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
    * Réalise un scan complet du système.
    * Sauvegarde le rapport en mode texte à l'issue du scan.

    4/ Edite le rapport AVGantispyware et le rapport Kaspersky.

    A demain.

    FillPCA
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. piloterepdom Messages postés 136 Statut Membre
     
    salut,
    peux t on conyinuer le nettoyage caR J AI EUDE NOUVEAU UN PROBLEME BIEN PLUSNQUE LENT ,,,,,IMPOSSIBLE SELECTIONNER ...J AI REFAIT UN NETTOYAGE EN MODE SANS ECHEC ET CELA VA MIEUX ....MAIS RIEN A LONG TERME JE PENSE .
    vOILA LE DERNIER HIYJACK .

    Juste spyboot a trouver ceci ...........SMITFRAUD- D-msvps et zlob donwnloader...

    ---------------------------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:34, on 2007-12-19
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Lexmark 2500 Series\lxddmon.exe
    C:\Program Files\Lexmark 2500 Series\lxddamon.exe
    C:\Program Files\NASDAK\OmniMouse Driver\4.1\MOUSE32A.EXE
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\PROGRA~1\LAUNCH~1\LManager.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\RTHDCPL.EXE
    c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\MSNMES~2\msnmsgr.exe
    C:\Program Files\UltraDVD\DVDMon.exe
    c:\program files\a-squared free\a2service.exe
    C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\lxddcoms.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    C:\DOCUME~1\jp\LOCALS~1\Temp\RtkBtMnt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\UAService7.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\MSN\MSNCoreFiles\msn6.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://fr.ca.acer.yahoo.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
    O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
    O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\NASDAK\OmniMouse Driver\4.1\MOUSE32A.EXE
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
    O4 - HKLM\..\Run: [Gnetmous] C:\Program Files\KYE\RF Wireless PowerScroll Mouse\gnetmous.exe
    O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
    O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~2\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [UltraDVDMon] "C:\Program Files\UltraDVD\DVDMon.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Photo Express SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
    O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe (file missing)
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
    0
  7. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Salut,

    Il me faut le rapport AVGantispyware et le rapport Kaspersky.

    FillPCA
    0
  8. piloterepdom Messages postés 136 Statut Membre
     
    ja i plus rien de tout cela ......je dopis recommencer et Avg je l ai supprimer ...........
    0
  9. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Re,

    Si je te les demande, c'est parce qu'ils me sont utiles.

    FillPCA
    0
  10. pilotrepdom
     
    voila le resultat , je reviens dansn une heure .les courses

    merci

    --------------------------------------------------

    AVG Anti-Spyware - Rapport d'analyse
    ---------------------------------------------------------

    + Créé à: 14:54 2007-12-20

    + Résultat de l'analyse:

    C:\Documents and Settings\jp\Cookies\jp@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
    C:\Documents and Settings\jp\Cookies\jp@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
    C:\Documents and Settings\jp\Cookies\jp@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
    C:\Documents and Settings\jp\Cookies\jp@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.

    Fin du rapport

    -----------------------------------------------------------------------------------------

    Thursday, December 20, 2007 11:08:40 AM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 20/12/2007
    Kaspersky Anti-Virus database records: 490289

    Scan Settings
    Scan using the following antivirus database extended
    Scan Archives true
    Scan Mail Bases true

    Scan Target My Computer
    C:\
    D:\
    E:\

    Scan Statistics
    Total number of scanned objects 94010
    Number of viruses found 3
    Number of infected objects 7
    Number of suspicious objects 0
    Duration of the scan process 01:17:53

    Infected Object Name Virus Name Last Action
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

    C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

    C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

    C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped

    C:\WINDOWS\Temp\Perflib_Perfdata_6b4.dat Object is locked skipped

    C:\WINDOWS\Temp\Perflib_Perfdata_b84.dat Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{6B7549AC-DD56-4C35-994F-AAF359BB500F}.crmlog Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\nretcip.exe Infected: not-a-virus:AdWare.Win32.Vapsup.qf skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

    C:\Documents and Settings\jp\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Temp\BIT30.tmp Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Historique\History.IE5\MSHist012007122020071221\index.dat Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Application Data\ApplicationHistory\ePower_DMC.exe.3ca0acde.ini.inuse Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\jp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\jp\ntuser.dat Object is locked skipped

    C:\Documents and Settings\jp\Bureau\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\Documents and Settings\jp\Bureau\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\Documents and Settings\jp\Bureau\mix\Nero-8.1.1.0b_fra_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

    C:\Documents and Settings\jp\Bureau\mix\Nero-8.1.1.0b_fra_trial.exe 7-Zip: infected - 1 skipped

    C:\Documents and Settings\jp\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\jp\Application Data\Sony Ericsson\Teleca\Telecalib\Logging\Application logs\TlibCmnDlgs_log.txt Object is locked skipped

    C:\Documents and Settings\jp\Application Data\Sony Ericsson\Teleca\Telecalib\Logging\Application logs\HookStarter_log.txt Object is locked skipped

    C:\Documents and Settings\jp\Application Data\Sony Ericsson\Teleca\Telecalib\Logging\Application logs\SpecificUSB_log.txt Object is locked skipped

    C:\Documents and Settings\jp\Application Data\Sony Ericsson\Teleca\Telecalib\Logging\Application logs\DM_log.txt Object is locked skipped

    C:\Documents and Settings\jp\Application Data\Sony Ericsson\Teleca\Telecalib\Logging\Application logs\appLauncher_all_log.txt Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\inuse.txt Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\main.log Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\storydb.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\storydb.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\chn.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\chn.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_die.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_die.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_dnd.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_dnd.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_ext.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_ext.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_rcv.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs_rcv.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\prs.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\chandir.dat Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\chandir.idx Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\D0000000.FCS Object is locked skipped

    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\jp\Data\L0000002.FCS Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped

    C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

    C:\system volume information\_restore{7D0A09CF-FCEC-40B1-949D-E158943906CC}\RP2\A0000081.exe/file09 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\system volume information\_restore{7D0A09CF-FCEC-40B1-949D-E158943906CC}\RP2\A0000081.exe Inno: infected - 1 skipped

    C:\system volume information\_restore{7D0A09CF-FCEC-40B1-949D-E158943906CC}\RP2\change.log Object is locked skipped

    C:\eDS_PSD_drive.vmdf Object is locked skipped

    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    Scan process completed.
    0
  11. piloterepdom
     
    merci so vous regarder mon probleme et m aider a le terminer
    0
  12. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Bonjour,

    Il faut arrêter avec les cracks. C'est la source principale d'infection.

    * Télécharge OTMoveIt (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
    * Double-clique sur OTMoveIt.exe pour lancer le programme,
    * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List Of Files/Folders to be moved" :

    C:\WINDOWS\nretcip.exe
    C:\Documents and Settings\jp\Bureau\mix\Nero-8.1.1.0b_fra_trial.exe


    * Clique sur MoveIt! pour lancer la suppression,
    * Le résultat appraraîtra dans le cadre Results.
    * Clique sur Exit pour fermer le programme.
    * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
    * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

    Edite ce rapport et dis-moi comment le pc se porte.

    FillPCA
    0
  13. piloterepdom Messages postés 136 Statut Membre
     
    salut,
    Merci de ton courrier et je te joins le rapport ....Mais je ne comprend pas ce vous dites d arreter les cracks .........expliquez moi et je verrais avec mes deux fils de quoi il retourne ...car je ne crack pas !! Merci

    File/Folder C:\WINDOWS\nretcip.exe not found.
    C:\Documents and Settings\jp\Bureau\mix\Nero-8.1.1.0b_fra_trial.exe moved successfully.

    Created on 12-21-2007 10:39:50

    File/Folder [nobackups] not found.
    File/Folder avenger.zip <Avenger by Swandog46> not found.
    File/Folder Avenger not found.
    File/Folder avenger.txt not found.
    File/Folder bfu.zip <BFU by Merijn> not found.
    File/Folder BFU not found.
    File/Folder combofix.exe <ComboFix by sUBs> not found.
    File/Folder QooBox not found.
    File/Folder ComboFix*.txt not found.
    File/Folder catchme.exe not found.
    File/Folder nircmd.exe not found.
    File/Folder swreg.exe not found.
    File/Folder Swxcacls.exe not found.
    File/Folder Swsc.exe not found.
    File/Folder dss.exe <Deckard's System Scanner by Deckard> not found.
    File/Folder Deckard not found.
    File/Folder FindAWF.exe <FindAWF by noahdfear> not found.
    File/Folder AWF.txt not found.
    File/Folder fixwareout.exe <FixWareout by LonnyRJones> not found.
    File/Folder fixwareout not found.
    File/Folder fsbl.exe <F-Secure BlackLight> not found.
    File/Folder fsbl*.log not found.
    File/Folder gmer.exe <GMER by Gmer> not found.
    File/Folder gmer.dll not found.
    File/Folder gmer.ini not found.
    File/Folder gmer.log not found.
    File/Folder gmer_uninstall.cmd not found.
    File/Folder gmer.sys not found.
    File/Folder gmer <delete service> not found.
    File/Folder haxfix.exe <Haxfix by Markie> not found.
    File/Folder haxfix.txt not found.
    File/Folder killbox.exe <Killbox by Option^Explicit> not found.
    File/Folder !Killbox not found.
    File/Folder NoLop.exe <NoLop by ?> not found.
    File/Folder NoLop.txt not found.
    File/Folder NoLopOLD.txt not found.
    File/Folder delete.bat not found.
    File/Folder OTMoveIt.exe <OTMoveIt by OldTimer> not found.
    File/Folder _OTMoveIt not found.
    File/Folder rustbfix.exe <Rustbfix by Ejvindh> not found.
    File/Folder Rustbfix not found.
    File/Folder sdfix.exe <SDFix by Andy_Manchesta> not found.
    File/Folder SDFix not found.
    File/Folder SmitfraudFix.exe <SmitfraudFix by S!Ri> not found.
    SmitfraudFix\SmitfraudFix moved successfully.
    SmitfraudFix\backups moved successfully.
    SmitfraudFix moved successfully.
    File/Folder rapport.txt not found.
    File/Folder SysInsite <System Insite by Bobbi Flekman> not found.
    File/Folder VundoFix.exe <VundoFix by Atribune> not found.
    File/Folder VundoFix Backups not found.
    File/Folder vundofix.txt not found.
    File/Folder vundofix.vft not found.
    File/Folder win32delfkil.exe <WinDelfKil by Markie> not found.
    File/Folder _backupD not found.
    File/Folder windelf.txt not found.
    File/Folder winpfind.exe <WinPfind by OldTimer> not found.
    File/Folder WinPfind not found.
    File/Folder winpfind3u.exe <WinPFind3 by OldTimer> not found.
    File/Folder WinPFind3u not found.
    File/Folder cleanup.txt not found.
    File/Folder [deleteself] not found.

    Created on 12-21-2007 10:40:17
    0
  14. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Re,

    Désolé, mais j'ai mal lu le rapport. C'est l'adware contenu dans un programme. Je te donne la suite ce soir. Comment le pc se porte-t-il ?

    FillPCA
    0
  15. piloterepdom Messages postés 136 Statut Membre
     
    merci pour le courrier ,
    Il va mieux , juste tres lent a l ouverture ....un test me donnait un port opuvert le 443/tcp et un virus SVCHOST virutal.....
    0
  16. piloterepdom Messages postés 136 Statut Membre
     
    hello
    0
  17. piloterepdom Messages postés 136 Statut Membre
     
    salut
    0
  18. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Bonsoir,

    J'aurai plus de temps en soirée. Quel est le virus détecté ? Par quel outil ?

    FillPCA
    0
  19. FillPCA Messages postés 2264 Statut Contributeur sécurité 123
     
    Re,

    Peux-tu me dire quel est l'outil qui détecte le virus?
    Je vois que tu n'as pas de pare-feu. Il faut en installer un.

    FillPCA
    0
Précédent
  • 1
  • 2