Virus Win32:AuCrypt xp19.com

Louchette Messages postés 4 Statut Membre -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,
Depuis peu, j'ai un virus xp19.com qui s'est installé sur mon disque dur externe via la connexion à un ordinateur qui me l'a refilé. Avast ne parvient pas à le supprimer, ce virus me bloqué l'accés au disque dur, j'ai utilisé flash desinfector pour supprimer les "Autorun.inf" Cela fait, il me reste un fichier dans mon disque dur "xp19.com" qui est une application MSDOS, j'aimerais savoir comment le supprimer ?
Merci.
Configuration: Windows XP
Firefox 2.0.0.13

5 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    1/ # Télécharge RavAntivirus d'Evosla :
    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
    # Retire tes disques amovibles et redémarrez votre ordinateur.
    # Poste le rapport, si infection!

    2/ as tu le nom exact du fichier avec le lien du genre D/ programme files........ ?

    3/

    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

    scan en ligne firefox

    https://www.trendmicro.com/fr_fr/business.html
    0
    1. Louchette Messages postés 4 Statut Membre
       
      Reuh, pour Rav il me dit que mon ordinateur est sain, sinan j'ai un rapport de combo fixe si ça te parle =/ (Ya des fichiers xp19 vers la fin) et je vais m'occuper du scan en ligne.

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
      .

      ((((((((((((((((((((((((((((( Fichiers créés 2008-03-02 to 2008-04-02 ))))))))))))))))))))))))))))))))))))
      .

      2008-03-31 19:47 . 2008-03-31 19:48 <REP> d-------- C:\WINDOWS\system32\NtmsData
      2008-03-31 18:54 . 2008-03-31 18:54 <REP> d-------- C:\Documents and Settings\Lil\Application Data\DataCast
      2008-03-31 18:54 . 2007-12-14 17:19 1,233,920 --------- C:\WINDOWS\system32\msxml4.dll
      2008-03-31 18:54 . 2008-02-01 08:40 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
      2008-03-31 18:54 . 2007-12-14 17:19 82,432 --------- C:\WINDOWS\system32\msxml4r.dll
      2008-03-31 18:54 . 2007-12-14 17:19 44,544 --------- C:\WINDOWS\system32\msxml4a.dll
      2008-03-31 18:39 . 2008-03-31 18:39 <REP> d-------- C:\Program Files\XviD
      2008-03-31 18:39 . 2008-03-31 18:39 <REP> d-------- C:\Program Files\Lame MP3 Codec
      2008-03-31 18:39 . 2002-12-03 22:13 1,048,576 --a------ C:\WINDOWS\system32\lameACM.acm
      2008-03-31 18:39 . 2005-05-03 09:33 299,008 --a------ C:\WINDOWS\system32\LAME_MP3.dll
      2008-03-31 18:39 . 2008-03-31 18:39 65,024 --a------ C:\WINDOWS\IFinst26.exe
      2008-03-31 18:39 . 2004-12-10 21:29 401 --a------ C:\WINDOWS\system32\lame_acm.xml
      2008-03-31 18:15 . 2008-03-31 18:15 <REP> d-------- C:\Program Files\Windows Media Connect 2
      2008-03-31 18:15 . 2006-10-04 10:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
      2008-03-31 18:15 . 2006-10-04 10:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
      2008-03-31 18:15 . 2006-10-04 10:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
      2008-03-31 18:13 . 2008-03-31 18:13 <REP> d-------- C:\WINDOWS\system32\LogFiles
      2008-03-31 18:13 . 2008-03-31 18:13 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
      2008-03-28 23:09 . 2008-03-29 00:04 <REP> d-------- C:\Program Files\EA GAMES
      2008-03-28 22:57 . 2004-08-18 04:34 442,368 -ra------ C:\WINDOWS\system32\vp6vfw.dll
      2008-03-25 00:30 . 2008-03-25 00:30 <REP> d-------- C:\Documents and Settings\Lil\Application Data\vlc
      2008-03-22 23:59 . 2008-03-22 23:59 268 --ah----- C:\sqmdata00.sqm
      2008-03-22 23:59 . 2008-03-22 23:59 244 --ah----- C:\sqmnoopt00.sqm
      2008-03-17 20:54 . 2008-03-17 20:54 38 --a------ C:\WINDOWS\AviSplitter.INI
      2008-03-17 15:34 . 2008-03-17 18:58 <REP> d-------- C:\sysreset
      2008-03-17 14:50 . 2008-03-17 14:52 <REP> d-------- C:\Program Files\mIRC
      2008-03-17 14:50 . 2008-03-17 15:34 <REP> d-------- C:\Documents and Settings\Lil\Application Data\mIRC
      2008-03-12 14:18 . 2008-03-12 14:18 <REP> d-------- C:\My Video
      2008-03-12 14:17 . 2008-03-12 14:17 <REP> d-------- C:\Program Files\Samsung
      2008-03-11 16:17 . 2007-02-09 07:10 574,464 -----c--- C:\WINDOWS\system32\dllcache\ntfs.sys
      2008-03-10 21:51 . 2008-03-10 21:51 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
      2008-03-10 21:43 . 2007-07-09 09:19 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
      2008-03-10 21:21 . 2007-03-17 09:44 293,376 -----c--- C:\WINDOWS\system32\dllcache\winsrv.dll
      2008-03-10 21:06 . 2008-03-10 21:06 <REP> d-------- C:\Program Files\LimeWire
      2008-03-10 21:02 . 2008-04-02 14:35 <REP> d-------- C:\Documents and Settings\Lil\.limewire
      2008-03-10 21:00 . 2007-04-16 11:53 1,049,600 -----c--- C:\WINDOWS\system32\dllcache\kernel32.dll
      2008-03-10 18:51 . 2006-08-21 05:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
      2008-03-10 18:51 . 2006-08-21 05:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
      2008-03-10 18:51 . 2006-08-21 08:26 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
      2008-03-09 22:36 . 2006-12-26 09:09 536,576 -----c--- C:\WINDOWS\system32\dllcache\msado15.dll
      2008-03-09 22:36 . 2006-12-26 09:09 200,704 -----c--- C:\WINDOWS\system32\dllcache\msadox.dll
      2008-03-09 22:36 . 2006-12-26 09:09 180,224 -----c--- C:\WINDOWS\system32\dllcache\msadomd.dll
      2008-03-09 22:36 . 2006-12-26 09:09 102,400 -----c--- C:\WINDOWS\system32\dllcache\msjro.dll
      2008-03-09 22:35 . 2006-08-14 06:34 332,928 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
      2008-03-09 22:27 . 2007-10-30 13:20 360,064 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
      2008-03-09 22:18 . 2007-10-29 18:43 1,293,824 -----c--- C:\WINDOWS\system32\dllcache\quartz.dll
      2008-03-09 22:05 . 2006-07-21 04:27 72,704 -----c--- C:\WINDOWS\system32\dllcache\hlink.dll
      2008-03-09 19:08 . 2006-09-25 17:58 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
      2008-03-09 18:42 . 2007-01-13 10:49 184,320 --a------ C:\WINDOWS\system32\igfxres.dll
      2008-03-09 18:38 . 2008-03-09 18:38 <REP> d-------- C:\Intel
      2008-03-09 18:37 . 2007-06-26 09:56 851,968 -----c--- C:\WINDOWS\system32\dllcache\vgx.dll
      2008-03-09 18:37 . 2006-10-12 07:54 256,512 -----c--- C:\WINDOWS\system32\dllcache\agentsvr.exe
      2008-03-09 18:37 . 2007-03-09 10:00 57,344 --a--c--- C:\WINDOWS\system32\dllcache\agentdpv.dll
      2008-03-09 18:37 . 2006-10-12 09:55 42,496 -----c--- C:\WINDOWS\system32\dllcache\agentdp2.dll
      2008-03-09 18:20 . 2008-03-09 18:20 <REP> d-------- C:\Program Files\ma-config.com
      2008-03-09 18:20 . 2008-03-09 18:20 <REP> d-------- C:\Documents and Settings\Lil\Application Data\ma-config.com
      2008-03-09 18:12 . 2006-06-26 13:41 148,480 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
      2008-03-09 18:12 . 2006-06-26 13:41 8,192 -----c--- C:\WINDOWS\system32\dllcache\rasadhlp.dll
      2008-03-09 12:52 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
      2008-03-09 12:52 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
      2008-03-09 12:52 . 2007-07-30 20:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
      2008-03-08 23:58 . 2008-03-08 23:58 <REP> d-------- C:\Documents and Settings\Lil\Application Data\Media Player Classic
      2008-03-08 23:50 . 2008-03-08 23:58 <REP> d-------- C:\Program Files\Satsuki Decoder Pack
      2008-03-08 21:22 . 2008-03-08 21:22 <REP> dr-h----- C:\Documents and Settings\Lil\Application Data\SecuROM
      2008-03-08 21:22 . 2008-03-08 21:22 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
      2008-03-08 21:21 . 2006-11-29 14:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
      2008-03-08 21:21 . 2006-12-08 13:02 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
      2008-03-08 21:21 . 2006-09-28 17:05 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
      2008-03-08 21:21 . 2006-11-15 12:38 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
      2008-03-08 21:20 . 2006-09-28 17:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
      2008-03-08 21:20 . 2006-07-28 10:30 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
      2008-03-08 21:20 . 2006-09-28 17:04 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
      2008-03-08 21:20 . 2006-07-28 10:30 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
      2008-03-08 21:16 . 2005-05-26 16:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
      2008-03-08 21:03 . 2008-03-08 21:47 <REP> d-------- C:\Program Files\Tomb Raider - Anniversary
      2008-03-08 20:32 . 2007-12-04 09:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
      2008-03-08 20:32 . 2004-01-09 05:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
      2008-03-08 20:32 . 2007-12-04 08:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
      2008-03-08 20:32 . 2007-12-04 10:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
      2008-03-08 20:32 . 2007-12-04 10:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
      2008-03-08 20:32 . 2007-12-04 10:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
      2008-03-08 20:32 . 2007-12-04 10:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
      2008-03-08 20:32 . 2007-12-04 10:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
      2008-03-08 19:12 . 2008-03-08 19:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
      2008-03-08 19:07 . 2008-03-08 19:07 <REP> d---s---- C:\Documents and Settings\Lil\UserData
      2008-03-08 18:05 . 2008-03-08 18:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Last.fm
      2008-03-08 17:35 . 2008-03-29 20:35 <REP> d-------- C:\Program Files\Messenger Plus! Live
      2008-03-08 17:33 . 2008-03-08 19:12 <REP> d-------- C:\WINDOWS\SxsCaPendDel
      2008-03-08 17:33 . 2008-03-08 17:33 <REP> d-------- C:\Program Files\Alwil Software
      2008-03-08 17:28 . 2008-03-08 17:31 <REP> d-------- C:\Program Files\Windows Live
      2008-03-08 17:28 . 2008-03-08 17:29 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
      2008-03-08 17:27 . 2008-03-08 17:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
      2008-03-08 16:54 . 2008-03-08 17:34 <REP> d-------- C:\Documents and Settings\Lil\Contacts
      2008-03-08 16:53 . 2008-03-08 16:53 <REP> d-------- C:\Documents and Settings\Lil\Application Data\Talkback
      2008-03-08 16:51 . 2008-03-09 18:39 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
      2008-03-08 16:50 . 2008-03-08 16:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
      2008-03-08 16:50 . 2008-03-08 23:58 26 --a------ C:\WINDOWS\system32\satsukidecodersettings.ini
      2008-03-08 16:49 . 2008-03-08 16:49 <REP> d-------- C:\Program Files\VideoLAN
      2008-03-08 16:49 . 2008-03-08 16:49 107,132 --a------ C:\WINDOWS\UninstallFirefox.exe
      2008-03-08 16:49 . 2008-03-08 17:20 3,447 --a------ C:\WINDOWS\mozver.dat

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-04-01 00:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-03-09 03:44 --------- d-----w C:\Program Files\Sonic
      2008-03-08 21:11 --------- d-----w C:\Program Files\microsoft frontpage
      2008-03-08 20:46 --------- d-----w C:\Program Files\Symantec
      2008-03-08 20:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
      2008-03-08 14:32 --------- d-----w C:\Program Files\InterVideo
      2008-03-08 14:30 --------- d-----w C:\Program Files\Toshiba
      2008-02-01 12:40 40,960 ----a-w C:\WINDOWS\system32\MAMACExtract.dll
      .

      ------- Sigcheck -------

      2004-08-05 06:00 14336 1bd6c2f707a275cb7c16fd99fe0f31ca C:\WINDOWS\system32\svchost.exe

      2004-08-05 06:00 82944 bc41f51a39d3b255805fdb759b7814ae C:\WINDOWS\system32\ws2_32.dll

      2005-05-02 16:58 663040 0996b57cc2abcb271872296e98a18db2 C:\WINDOWS\$hf_mig$\KB883939\SP2QFE\wininet.dll
      2005-03-10 03:48 662016 06ad0b0f43286cd50af283762eb56763 C:\WINDOWS\$hf_mig$\KB890923\SP2QFE\wininet.dll
      2004-08-05 06:00 660480 58fe94ef42e074f4cad8bf02e70e6478 C:\WINDOWS\$NtUninstallKB883939$\wininet.dll
      2005-05-02 16:57 662016 ffe3e6fb8d52955a2de4c6cc765b02bc C:\WINDOWS\SoftwareDistribution\Download\29232188b30706c8db3d1b4e5465b0b9\backup\sp2gdr\wininet.dll
      2005-05-02 16:57 662016 ffe3e6fb8d52955a2de4c6cc765b02bc C:\WINDOWS\SoftwareDistribution\Download\29232188b30706c8db3d1b4e5465b0b9\backup\sp2qfe\wininet.dll
      2005-05-02 16:57 662016 ffe3e6fb8d52955a2de4c6cc765b02bc C:\WINDOWS\system32\wininet.dll

      2005-05-25 15:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
      2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
      2004-08-05 06:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
      2005-05-25 15:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
      2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\dllcache\tcpip.sys
      2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\drivers\tcpip.sys

      2004-08-05 06:00 506368 d2de785aeab0bb8ca4c14a8a199dbe4e C:\WINDOWS\system32\winlogon.exe

      2004-08-05 06:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

      2004-08-05 06:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

      2007-02-28 12:08 2061440 7a56a64eb50399613587e90292dd2aab C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
      2004-08-05 06:00 2058880 f252fae094c54572ece38a039f2103c4 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
      2007-02-28 12:02 2059648 a1d5231403329478ae4fe2778c55c77f C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
      2004-08-05 06:00 2058880 f252fae094c54572ece38a039f2103c4 C:\WINDOWS\SoftwareDistribution\Download\9ba9675594796c70a279084c24cd7675\backup\sp2gdr\ntkrnlpa.exe
      2004-08-04 01:48 2058880 f252fae094c54572ece38a039f2103c4 C:\WINDOWS\SoftwareDistribution\Download\9ba9675594796c70a279084c24cd7675\backup\sp2qfe\ntkrnlpa.exe
      2007-02-28 12:02 2059648 a1d5231403329478ae4fe2778c55c77f C:\WINDOWS\system32\ntkrnlpa.exe
      2007-02-28 12:02 2059648 a1d5231403329478ae4fe2778c55c77f C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

      2007-02-28 12:08 2184192 8e244108562e0e452eb68dff64cb08a9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
      2004-08-05 06:00 2183040 7d38ce4398e6aa6339b4644feadcc0d8 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
      2007-02-28 12:02 2182400 7d6d19aac51a4325f6039f083c22303c C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
      2004-08-05 06:00 2183040 7d38ce4398e6aa6339b4644feadcc0d8 C:\WINDOWS\SoftwareDistribution\Download\9ba9675594796c70a279084c24cd7675\backup\sp2gdr\ntoskrnl.exe
      2004-08-04 01:49 2183040 7d38ce4398e6aa6339b4644feadcc0d8 C:\WINDOWS\SoftwareDistribution\Download\9ba9675594796c70a279084c24cd7675\backup\sp2qfe\ntoskrnl.exe
      2007-02-28 12:02 2182400 7d6d19aac51a4325f6039f083c22303c C:\WINDOWS\system32\ntoskrnl.exe
      2007-02-28 12:02 2182400 7d6d19aac51a4325f6039f083c22303c C:\WINDOWS\system32\dllcache\ntoskrnl.exe

      2007-06-13 09:22 1037312 d0288319660edcfed07c7e74c4ea38a5 C:\WINDOWS\explorer.exe
      2007-06-13 09:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
      2004-08-05 06:00 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
      2007-06-13 09:22 1037312 d0288319660edcfed07c7e74c4ea38a5 C:\WINDOWS\system32\dllcache\explorer.exe
      .
      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 06:00 15360]
      "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 10:08 65536]
      "SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 18:03 683520]
      "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-06 13:16 184320]
      "AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 04:10 88358 C:\WINDOWS\agrsmmsg.exe]
      "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 01:40 196608]
      "CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 08:04 671744]
      "TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2005-08-25 13:11 53248]
      "HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 07:45 28672]
      "SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 07:45 65536]
      "Zooming"="ZoomingHook.exe" [2005-06-06 03:58 24576 C:\WINDOWS\system32\ZoomingHook.exe]
      "TCtryIOHook"="TCtrlIOHook.exe" [2005-08-22 10:49 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
      "TPSMain"="TPSMain.exe" [2005-08-12 05:14 266240 C:\WINDOWS\system32\TPSMain.exe]
      "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 03:24 118784]
      "TFncKy"="TFncKy.exe" []
      "PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-08-30 06:31 1077328]
      "Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 10:25 73728]
      "NDSTray.exe"="NDSTray.exe" []
      "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-30 23:33 122941]
      "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 16:09 157592]
      "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 18:54 37376]
      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 09:00 79224]
      "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-01-13 10:47 131072]
      "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-01-13 10:47 163840]
      "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-01-13 10:46 135168]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 06:00 15360]

      C:\Documents and Settings\Lil\Menu D‚marrer\Programmes\D‚marrage\
      Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-03-08 16:47:22 106496]

      C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-13 22:44:06 29696]

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "C:\\Program Files\\Last.fm\\LastFM.exe"=
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "C:\\Program Files\\LimeWire\\LimeWire.exe"=
      "C:\\Program Files\\mIRC\\mirc.exe"=
      "C:\\sysreset\\mirc.exe"=

      S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-03-24 10:36]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cb25676-f2a7-11dc-a8ca-000fb08ddaa7}]
      \Shell\AutoRun\command - E:\xp19.com
      \Shell\explore\Command - E:\xp19.com
      \Shell\open\Command - E:\xp19.com

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{becca7d6-f5da-11dc-a8d1-000fb08ddaa7}]
      \Shell\AutoRun\command - x6.bat
      \Shell\explore\Command - x6.bat
      \Shell\open\Command - x6.bat

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed9f2c26-f361-11dc-a8cb-000fb08ddaa7}]
      \Shell\AutoRun\command - E:\xp19.com
      \Shell\explore\Command - E:\xp19.com
      \Shell\open\Command - E:\xp19.com

      .
      **************************************************************************

      catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-04-02 16:25:41
      Windows 5.1.2600 Service Pack 2 NTFS

      Balayage processus cachés ...

      Balayage caché autostart entries ...

      Balayage des fichiers cachés ...

      Scan terminé avec succès
      Les fichiers cachés: 0

      **************************************************************************
      .
      Temps d'accomplissement: 2008-04-02 16:26:22
      ComboFix-quarantined-files.txt 2008-04-02 20:26:06
      ComboFix2.txt 2008-04-02 17:33:24
      ComboFix3.txt 2008-04-02 17:30:48
      Pre-Run: 20,348,936,192 octets libres
      Post-Run: 20,340,408,320 octets libres
      0
  2. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    analyse le fichier sur virus total et si infécté: tu fais la suite:

    https://www.virustotal.com/gui/

    E:\xp19.com

    __________________

    Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)

    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    File::
    E:\xp19.com

    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cb256­76-f2a7-11dc-a8ca-000fb08ddaa7}]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed9f2c­26-f361-11dc-a8cb-000fb08ddaa7}]

    Enregistre ce fichier sous le nom CFscript

    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

    Remets aussi un rapport Hijackthis

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
    1. Louchette Messages postés 4 Statut Membre
       
      Pour le E:/ Je l'ai pas '_' En fait, j'ai branché mon mp3 mais je pense qu'il est également infecté parce que l'ordinateur le detecte mais rien de plus, je peux pas y acceder parce qu'il ne s'affiche nul part, est ce que ça pourrait etre ça ? Si oui comment je l'analyse si je le voit pas ?
      0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    il faut branché ton lecteur E (donc le mp3 ) puis refaire ceci

    1/ # Télécharge RavAntivirus d'Evosla :
    http://ww25.evosla.com/compteur.php?soft=rav_antivirus

    # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
    # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
    # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
    # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
    # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
    # Retire tes disques amovibles et redémarrez votre ordinateur.
    # Poste le rapport, si infection!

    2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

    Double-clique sur l’icône.
    Les icônes vont disparaître. C’est normal.
    Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
    Redémarre ensuite le PC.

    3/

    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

    scan en ligne firefox

    https://www.trendmicro.com/fr_fr/business.html
    0
  4. Louchette Messages postés 4 Statut Membre
     
    Euh, ça marche pas, quand je mets le document texte sur l'icone il me lançe un scan normal, sans me poser de question avant. Pour le mp3 c'est toujours pareil malgrés flash desinfector que j'ai refais. C'est un peu la misère ce truc. Et pour le scan en ligne, bit defender m'avait trouvé le fichier xp19.com sur le disque dur, il me dit qu'il à supprimé mais il y est encore. Donc je suis un peu paumée là.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    tu aurais le rapport bitdefendr?

    ___________

    fais ceci

    Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)

    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    File::
    E:\xp19.com

    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cb256­­76-f2a7-11dc-a8ca-000fb08ddaa7}]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed9f2c­­26-f361-11dc-a8cb-000fb08ddaa7}]

    Enregistre ce fichier sous le nom CFscript

    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

    Remets aussi un rapport Hijackthis

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0