A l'aide ! malware , trojan et compagnie !
Fermé
lilyne69
Messages postés
29
Statut
Membre
-
lilyne69 Messages postés 29 Statut Membre -
lilyne69 Messages postés 29 Statut Membre -
bonjour a tous !
jai tout un tas de virus malware , trojan .... et je voudrais m'en debarasser !
j'ai telechargé hijackthis et voici le resultat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:21, on 15-05-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RegSrvc.exe
c:\windows\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\msNTNSslog.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\MMTray.exe
C:\WINDOWS\system32\MMTray2k.exe
C:\WINDOWS\system32\MMTrayLSI.exe
C:\WINDOWS\vsnpstd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\sysmgr.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINDOWS\system32\logon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
D:\spftray.exe
D:\spfprc.exe
D:\SPYWAREfighter.exe
C:\WINDOWS\system32\freecell.exe
C:\Programas\Alwil Software\Avast4\ashChest.exe
C:\Programas\FreeCall.com\FreeCall\FreeCall.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Mary\Definições locais\Temporary Internet Files\Content.IE5\ARQ7E5CB\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pt/webhp?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\secpol.exe,
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Programas\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programas\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ClamWin] "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Regen] "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\sysmgr.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [spywarefighterguard] D:\spftray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Programas\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Programas\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm451YYPT
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MBNet-Sidebar - {C014B140-3835-11d6-BC1D-00C095EEAD5D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} (MBNet) - https://www.mbnet.pt/sidebar/mbnetsidebar.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - https://copainsdavant.linternaute.com/
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDB6845C-00C0-4B24-BCEC-FAC7B9C946FF}: NameServer = 195.23.129.126,194.79.69.222
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: fsmgmt - C:\WINDOWS\SYSTEM32\fsmgmt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: netimon - Unknown owner - C:\WINDOWS\system\netimon.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - D:\spfprc.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mary/DEFINI~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - http://www2.expresso.com.br/clientes/blogcarmen/presentenatal.gif
jai egalement telechargé spybot et spyware figther.
j'imerai savoir si je peu effacer sans risques les virus que ces deu programmes m'on touvés.
i me semble que certains virus se trouvent dans le sisteme et je ne voudrais rien perdre ...
au secours !
jai tout un tas de virus malware , trojan .... et je voudrais m'en debarasser !
j'ai telechargé hijackthis et voici le resultat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:21, on 15-05-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RegSrvc.exe
c:\windows\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\msNTNSslog.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\MMTray.exe
C:\WINDOWS\system32\MMTray2k.exe
C:\WINDOWS\system32\MMTrayLSI.exe
C:\WINDOWS\vsnpstd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\sysmgr.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINDOWS\system32\logon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
D:\spftray.exe
D:\spfprc.exe
D:\SPYWAREfighter.exe
C:\WINDOWS\system32\freecell.exe
C:\Programas\Alwil Software\Avast4\ashChest.exe
C:\Programas\FreeCall.com\FreeCall\FreeCall.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Mary\Definições locais\Temporary Internet Files\Content.IE5\ARQ7E5CB\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pt/webhp?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\secpol.exe,
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Programas\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programas\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ClamWin] "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Regen] "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\sysmgr.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [spywarefighterguard] D:\spftray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Programas\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Programas\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm451YYPT
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MBNet-Sidebar - {C014B140-3835-11d6-BC1D-00C095EEAD5D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} (MBNet) - https://www.mbnet.pt/sidebar/mbnetsidebar.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - https://copainsdavant.linternaute.com/
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDB6845C-00C0-4B24-BCEC-FAC7B9C946FF}: NameServer = 195.23.129.126,194.79.69.222
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: fsmgmt - C:\WINDOWS\SYSTEM32\fsmgmt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: netimon - Unknown owner - C:\WINDOWS\system\netimon.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - D:\spfprc.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mary/DEFINI~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - http://www2.expresso.com.br/clientes/blogcarmen/presentenatal.gif
jai egalement telechargé spybot et spyware figther.
j'imerai savoir si je peu effacer sans risques les virus que ces deu programmes m'on touvés.
i me semble que certains virus se trouvent dans le sisteme et je ne voudrais rien perdre ...
au secours !
A voir également:
- A l'aide ! malware , trojan et compagnie !
- Malwarebytes anti-malware - Télécharger - Antivirus & Antimalwares
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Mcafee malware - Accueil - Piratage
- Paroles de la compagnie créole a.i.e. (a moun'la) traduction ✓ - Forum Musique / Radio / Clip
- Supprimer malware - Guide
3 réponses
Tu fais un scan en mode sans échec avec AntiVir. Tu lances le scan et si il détecte un virus (normalement oui) tu cliques sur "delete" et "apply sélection to all following détections. (pour qu'il le supprimes automatiquement). A la fin du scan tu cliques sur "report" tu redémarre en mode normal puis tu me postes le rapport.
Mode sans Echec:
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
PS: JE TE CONSEILLE D'ENREGISTRER CE MESSAGE DANS TON BUREAU OU CAS OU.
Mode sans Echec:
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
PS: JE TE CONSEILLE D'ENREGISTRER CE MESSAGE DANS TON BUREAU OU CAS OU.
desolée de revenir si tard, mais ca a pris un temps fou !
voila le rapoort
merci de maider pour le prochain pas ... j'espere que mon ordi n'a rien de grave !
Avira AntiVir Personal
Report file date: quinta-feira, 15 de Maio de 2008 19:09
Scanning for 1274495 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Mary
Computer name: COMPMARY
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09-04-2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18-03-2008 10:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07-02-2008 09:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28-02-2008 09:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21-02-2008 09:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18-07-2007 11:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07-03-2008 14:08:58
ANTIVIR2.VDF : 7.0.4.0 1554432 Bytes 05-05-2008 17:41:51
ANTIVIR3.VDF : 7.0.4.46 307712 Bytes 15-05-2008 17:42:00
Engineversion : 8.1.0.46
AEVDF.DLL : 8.1.0.5 102772 Bytes 25-02-2008 10:58:21
AESCRIPT.DLL : 8.1.0.33 266618 Bytes 15-05-2008 17:43:07
AESCN.DLL : 8.1.0.18 119156 Bytes 15-05-2008 17:43:02
AERDL.DLL : 8.1.0.20 418165 Bytes 15-05-2008 17:43:01
AEPACK.DLL : 8.1.1.5 364918 Bytes 15-05-2008 17:42:54
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 15-05-2008 17:42:47
AEHEUR.DLL : 8.1.0.29 1253750 Bytes 15-05-2008 17:42:43
AEHELP.DLL : 8.1.0.14 115063 Bytes 15-05-2008 17:42:20
AEGEN.DLL : 8.1.0.21 303477 Bytes 15-05-2008 17:42:18
AEEMU.DLL : 8.1.0.6 430451 Bytes 15-05-2008 17:42:09
AECORE.DLL : 8.1.0.29 168311 Bytes 15-05-2008 17:42:06
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23-01-2008 18:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18-02-2008 11:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16-04-2007 14:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23-01-2008 18:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12-02-2008 09:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28-02-2008 09:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22-01-2008 18:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23-01-2008 18:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25-01-2008 13:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10-03-2008 15:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06-03-2008 13:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programas\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: quinta-feira, 15 de Maio de 2008 19:09
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
13 processes with 13 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] O dispositivo não está preparado.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
C:\WINDOWS\system32\fsmgmt.dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[WARNING] The file could not be deleted!
C:\WINDOWS\system32\sysmgr.exe
[DETECTION] Is the Trojan horse TR/Spy.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\logon.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was deleted!
The registry was scanned ( '46' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\6GH078UG\client[1].exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Small.dls Backdoor server programs
[NOTE] The file was deleted!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\6GH078UG\loadered[1].exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\XS8FYBFP\client[1].exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Small.dls Backdoor server programs
[NOTE] The file was deleted!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\XS8FYBFP\kav22[1].exe
[DETECTION] Is the Trojan horse TR/Spy.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\Mary\12083792812660.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Small.dls Backdoor server programs
[NOTE] The file was deleted!
C:\RECYCLER\NPROTECT\00044112.exe
[DETECTION] Is the Trojan horse TR/Dldr.FakeAV.A.5
[NOTE] The file was deleted!
C:\WINDOWS\msNTNSslog.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\ fsmgmt.dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\ fsmgmt.dll.tmp
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\fsmgmt.dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[WARNING] The file could not be deleted!
C:\WINDOWS\system32\secpol.exe
[DETECTION] Contains detection pattern of the worm WORM/Autorun.drr
[NOTE] The file was deleted!
C:\WINDOWS\system32\config\systemprofile\Definições locais\Temporary Internet Files\Content.IE5\7HRS23DW\NewServer[1].dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\config\systemprofile\Definições locais\Temporary Internet Files\Content.IE5\IAKU45OG\NewServer[1].dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\config\systemprofile\Definições locais\Temporary Internet Files\Content.IE5\IAKU45OG\NewServer[2].dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
Begin scan in 'D:\'
End of the scan: quinta-feira, 15 de Maio de 2008 20:57
Used time: 1:47:33 min
The scan has been done completely.
7218 Scanning directories
331832 Files were scanned
17 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
15 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
331815 Files not concerned
1636 Archives were scanned
4 Warnings
15 Notes
voila le rapoort
merci de maider pour le prochain pas ... j'espere que mon ordi n'a rien de grave !
Avira AntiVir Personal
Report file date: quinta-feira, 15 de Maio de 2008 19:09
Scanning for 1274495 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Mary
Computer name: COMPMARY
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09-04-2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18-03-2008 10:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07-02-2008 09:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28-02-2008 09:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21-02-2008 09:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18-07-2007 11:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07-03-2008 14:08:58
ANTIVIR2.VDF : 7.0.4.0 1554432 Bytes 05-05-2008 17:41:51
ANTIVIR3.VDF : 7.0.4.46 307712 Bytes 15-05-2008 17:42:00
Engineversion : 8.1.0.46
AEVDF.DLL : 8.1.0.5 102772 Bytes 25-02-2008 10:58:21
AESCRIPT.DLL : 8.1.0.33 266618 Bytes 15-05-2008 17:43:07
AESCN.DLL : 8.1.0.18 119156 Bytes 15-05-2008 17:43:02
AERDL.DLL : 8.1.0.20 418165 Bytes 15-05-2008 17:43:01
AEPACK.DLL : 8.1.1.5 364918 Bytes 15-05-2008 17:42:54
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 15-05-2008 17:42:47
AEHEUR.DLL : 8.1.0.29 1253750 Bytes 15-05-2008 17:42:43
AEHELP.DLL : 8.1.0.14 115063 Bytes 15-05-2008 17:42:20
AEGEN.DLL : 8.1.0.21 303477 Bytes 15-05-2008 17:42:18
AEEMU.DLL : 8.1.0.6 430451 Bytes 15-05-2008 17:42:09
AECORE.DLL : 8.1.0.29 168311 Bytes 15-05-2008 17:42:06
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23-01-2008 18:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18-02-2008 11:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16-04-2007 14:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23-01-2008 18:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12-02-2008 09:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28-02-2008 09:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22-01-2008 18:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23-01-2008 18:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25-01-2008 13:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10-03-2008 15:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06-03-2008 13:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programas\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: quinta-feira, 15 de Maio de 2008 19:09
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
13 processes with 13 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] O dispositivo não está preparado.
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
C:\WINDOWS\system32\fsmgmt.dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[WARNING] The file could not be deleted!
C:\WINDOWS\system32\sysmgr.exe
[DETECTION] Is the Trojan horse TR/Spy.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\logon.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was deleted!
The registry was scanned ( '46' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\6GH078UG\client[1].exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Small.dls Backdoor server programs
[NOTE] The file was deleted!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\6GH078UG\loadered[1].exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\XS8FYBFP\client[1].exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Small.dls Backdoor server programs
[NOTE] The file was deleted!
C:\Documents and Settings\LocalService\Definições locais\Temporary Internet Files\Content.IE5\XS8FYBFP\kav22[1].exe
[DETECTION] Is the Trojan horse TR/Spy.Gen
[NOTE] The file was deleted!
C:\Documents and Settings\Mary\12083792812660.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Small.dls Backdoor server programs
[NOTE] The file was deleted!
C:\RECYCLER\NPROTECT\00044112.exe
[DETECTION] Is the Trojan horse TR/Dldr.FakeAV.A.5
[NOTE] The file was deleted!
C:\WINDOWS\msNTNSslog.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\ fsmgmt.dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\ fsmgmt.dll.tmp
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\fsmgmt.dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[WARNING] The file could not be deleted!
C:\WINDOWS\system32\secpol.exe
[DETECTION] Contains detection pattern of the worm WORM/Autorun.drr
[NOTE] The file was deleted!
C:\WINDOWS\system32\config\systemprofile\Definições locais\Temporary Internet Files\Content.IE5\7HRS23DW\NewServer[1].dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\config\systemprofile\Definições locais\Temporary Internet Files\Content.IE5\IAKU45OG\NewServer[1].dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
C:\WINDOWS\system32\config\systemprofile\Definições locais\Temporary Internet Files\Content.IE5\IAKU45OG\NewServer[2].dll
[DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen
[NOTE] The file was deleted!
Begin scan in 'D:\'
End of the scan: quinta-feira, 15 de Maio de 2008 20:57
Used time: 1:47:33 min
The scan has been done completely.
7218 Scanning directories
331832 Files were scanned
17 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
15 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
331815 Files not concerned
1636 Archives were scanned
4 Warnings
15 Notes
j'avais norton mais je l'ai supprimé il y a quelque mois apres expiration.
j'ai egalement adaware que jutilise regulierement.
AntiVir: https://www.01net.com/outils/telecharger/windows/Securite/antivirus-antitrojan/fiches/tele13198.html
Tutoriel AntiVir: https://www.malekal.com/avira-free-security-antivirus-gratuit/
Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
Ccleaner: https://www.01net.com/outils/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/tele32599.html
Tutoriel Ccleaner: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php (Tu l'installe sans la bare d'outil Yahoo)
PS: TU LES INSTALLES SEULEMENT ET TU NE FAIS PAS D'ANALYSE. TU FAIS UNE MISE A JOUR A ANTIVIR ET MALWAREBYTES ANTI-MALWARE.
et j'ai le resultat d'analyse de spybot avec une liste de virus a effacer ... qu'est-ce que j'en fait ?
je les efface ?