7 virus!!help please - Page 2

  1. ensuite :

    Télécharge
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
    sur ton Bureau et lance le.

    Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée.

    Copie et colle les ligne ci-dessous dans l'encadré bleue de OTMoveIt nommé Paste Standard List of Files/Folders to move.

    c:\windows\wrkstn.exe
    c:\windows\regscan32.exe
    c:\windows\w32usb2.exe
    c:\windows\sysentry32.exe
    c:\windows\scmlog.exe
    c:\windows\winupdt.exe
    c:\windows\muamgrd.exe
    c:\windows\ms32cfg.exe
    c:\windows\directx64.exe
    c:\windows\logon.exe
    c:\windows\msnplugins.exe
    c:\windows\s32mlog.exe
    c:\windows\system32\wrkstn.exe
    c:\windows\system32\regscan32.exe
    c:\windows\system32\w32usb2.exe
    c:\windows\system32\sysentry32.exe
    c:\windows\system32\scmlog.exe
    c:\windows\system32\winupdt.exe
    c:\windows\system32\muamgrd.exe
    c:\windows\system32\ms32cfg.exe
    c:\windows\system32\directx64.exe
    c:\windows\system32\logon.exe
    c:\windows\system32\msnplugins.exe
    c:\windows\system32\s32mlog.exe

    Clique sur MoveIt! pour lancer la suppression.
    Si OTMoveIt propose de redémarrer ton PC, accepte !
    Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.

    Dans ta future réponse, envoie le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles
    0
    1. g bien suivi t conseil mai dan results ca remark toutes les adresse mai avec not found apres
      0
      1. c'est possible, c'est par précaution :)

        ta encore des soucis? ta mis antivir à jour? j'ai vu que tu avais du norton désinstalle le et met à jour windows
        0
        1. ben jarrive ni a mettre a jour antivir et ni a viré norton completement.... dapres moi javai viré norton mai dapres ske tu me di il est encore la et ca metonne pa dailleurs....
          0
          1. Pour norton :
            http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

            tu selection ta version puis tu télécharge uninstaller après

            Pour antivir, il met quoi ?
            0
            1. et ske g mi en karantaine avec antivir fo je suprime ou pa?
              ok pour norton je vai essayer je te demande si ca march pa... ok?
              0
              1. commen je c kel version etai dan lordi?
                pour antivir ca me di "internet connection failed" pi je peu ouvrir un rapport ke je tai mi plu o! tu la pa recu?
                0
                1. et apres c bon y aura pu de composan norton ni avast?
                  les mis a jours de antivir marche tjs! pourkoi?
                  0
                  1. a ben nortan a voulu redemarré. apres il a voulu ke je reinstal norton mdr c con un pc
                    pi les mis a jour de antivar on fonctionné!!!
                    donc c bon y a pu de virus et tou?
                    pc correcte?
                    0
                    1. ben c'est à toid e le dire, refait un scan avec antivir à jour et les msie a jour de windows.
                      0
                      1. ok je fai ca et je te di apres
                        pour linstan antivir a juste marké :
                        warnings 2
                        mais ca a pa lair de le deranger....
                        0
                        1. non warning c'est les fichiers systeme en cours execution

                          exemple :
                          [WARNING] The file could not be opened!

                          le fichier ne peut pas etre ouvert ( en gros)
                          mais c'est normal
                          0
                          1. antivir

                            Avira AntiVir Personal
                            Report file date: dimanche 25 mai 2008 22:51

                            Scanning for 1287458 virus strains and unwanted programs.

                            Licensed to: Avira AntiVir PersonalEdition Classic
                            Serial number: 0000149996-ADJIE-0001
                            Platform: Windows XP
                            Windows version: (Service Pack 1) [5.1.2600]
                            Boot mode: Normally booted
                            Username: LEPOUTRE Dominique
                            Computer name: DOLEP

                            Version information:
                            BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
                            AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:58
                            AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:38
                            LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:24
                            LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:42
                            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                            ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
                            ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 17/05/2008 20:48:54
                            ANTIVIR3.VDF : 7.0.4.89 171520 Bytes 25/05/2008 20:48:56
                            Engineversion : 8.1.0.46
                            AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:22
                            AESCRIPT.DLL : 8.1.0.33 266618 Bytes 25/05/2008 20:49:08
                            AESCN.DLL : 8.1.0.18 119156 Bytes 25/05/2008 20:49:08
                            AERDL.DLL : 8.1.0.20 418165 Bytes 25/05/2008 20:49:06
                            AEPACK.DLL : 8.1.1.5 364918 Bytes 25/05/2008 20:49:04
                            AEOFFICE.DLL : 8.1.0.18 192890 Bytes 25/05/2008 20:49:04
                            AEHEUR.DLL : 8.1.0.29 1253750 Bytes 25/05/2008 20:49:02
                            AEHELP.DLL : 8.1.0.14 115063 Bytes 25/05/2008 20:48:58
                            AEGEN.DLL : 8.1.0.21 303477 Bytes 25/05/2008 20:48:58
                            AEEMU.DLL : 8.1.0.6 430451 Bytes 25/05/2008 20:48:58
                            AECORE.DLL : 8.1.0.29 168311 Bytes 25/05/2008 20:48:56
                            AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:54
                            AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:52
                            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:48
                            AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:50
                            AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:24
                            AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:32
                            SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
                            SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:40
                            NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:12
                            RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:26
                            RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:12

                            Configuration settings for the scan:
                            Jobname..........................: Local Drives
                            Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
                            Logging..........................: low
                            Primary action...................: interactive
                            Secondary action.................: ignore
                            Scan master boot sector..........: on
                            Scan boot sector.................: on
                            Boot sectors.....................: C:, D:, E:,
                            Scan memory......................: on
                            Process scan.....................: on
                            Scan registry....................: on
                            Search for rootkits..............: off
                            Scan all files...................: Intelligent file selection
                            Scan archives....................: on
                            Recursion depth..................: 20
                            Smart extensions.................: on
                            Macro heuristic..................: on
                            File heuristic...................: medium

                            Start of the scan: dimanche 25 mai 2008 22:51

                            The scan of running processes will be started
                            Scan process 'avscan.exe' - '1' Module(s) have been scanned
                            Scan process 'AVCENTER.EXE' - '1' Module(s) have been scanned
                            Scan process 'AVGNT.EXE' - '1' Module(s) have been scanned
                            Scan process 'WUAUCLT.EXE' - '1' Module(s) have been scanned
                            Scan process 'WUAUCLT.EXE' - '1' Module(s) have been scanned
                            Scan process 'AVGUARD.EXE' - '1' Module(s) have been scanned
                            Scan process 'ALG.EXE' - '1' Module(s) have been scanned
                            Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
                            Scan process 'DSLMON.EXE' - '1' Module(s) have been scanned
                            Scan process 'MSMSGS.EXE' - '1' Module(s) have been scanned
                            Scan process 'CTFMON.EXE' - '1' Module(s) have been scanned
                            Scan process 'AGRSMMSG.EXE' - '1' Module(s) have been scanned
                            Scan process 'CPLBCL53.EXE' - '1' Module(s) have been scanned
                            Scan process 'WINAMPA.EXE' - '1' Module(s) have been scanned
                            Scan process 'Apoint.exe' - '1' Module(s) have been scanned
                            Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
                            Scan process 'HKCMD.EXE' - '1' Module(s) have been scanned
                            Scan process 'IGFXTRAY.EXE' - '1' Module(s) have been scanned
                            Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
                            Scan process 'SCHED.EXE' - '1' Module(s) have been scanned
                            Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
                            Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                            Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                            Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                            Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                            Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
                            Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
                            Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
                            Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
                            Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
                            30 processes with 30 modules were scanned

                            Starting master boot sector scan:
                            Master boot sector HD0
                            [INFO] No virus was found!

                            Start scanning boot sectors:
                            Boot sector 'C:\'
                            [INFO] No virus was found!
                            Boot sector 'D:\'
                            [INFO] No virus was found!

                            Starting to scan the registry.
                            The registry was scanned ( '35' files ).

                            Starting the file scan:

                            Begin scan in 'C:\' <ACER>
                            C:\pagefile.sys
                            [WARNING] The file could not be opened!
                            C:\hiberfil.sys
                            [WARNING] The file could not be opened!
                            Begin scan in 'D:\' <ACERDATA>
                            Begin scan in 'E:\'
                            Search path E:\ could not be opened!
                            Le périphérique n'est pas prêt.

                            End of the scan: dimanche 25 mai 2008 23:06
                            Used time: 15:11 min

                            The scan has been done completely.

                            2194 Scanning directories
                            130087 Files were scanned
                            0 viruses and/or unwanted programs were found
                            0 Files were classified as suspicious:
                            0 files were deleted
                            0 files were repaired
                            0 files were moved to quarantine
                            0 files were renamed
                            2 Files cannot be scanned
                            130087 Files not concerned
                            6699 Archives were scanned
                            2 Warnings
                            0 Notes

                            hijackthis

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 23:09:44, on 25/05/2008
                            Platform: Windows XP SP1 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\System32\igfxtray.exe
                            C:\WINDOWS\System32\hkcmd.exe
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\Program Files\Apoint2K\Apoint.exe
                            C:\Program Files\Winamp3\winampa.exe
                            C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
                            C:\WINDOWS\AGRSMMSG.exe
                            C:\WINDOWS\System32\ctfmon.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                            C:\Program Files\Apoint2K\Apntex.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            C:\WINDOWS\System32\wuauclt.exe
                            C:\WINDOWS\System32\wuauclt.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                            c:\program files\avira\antivir personaledition classic\avcenter.exe
                            c:\program files\avira\antivir personaledition classic\avscan.exe
                            C:\WINDOWS\System32\notepad.exe
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Documents and Settings\LEPOUTRE Dominique\Bureau\HiJackThisg.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                            O2 - BHO: (no name) - {32AA657D-B53A-2EE0-8754-605508A22636} - (no file)
                            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                            O4 - HKLM\..\Run: [LaunchApp] Alaunch
                            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
                            O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
                            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                            O4 - HKLM\..\Run: [adiras] adiras.exe
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                            O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                            O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                            O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
                            0
                            1. ah g pa encore fai les mises a jour windows enfait....
                              0
                              1. tu l'avais fixé ?

                                O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)

                                parce qu'il y est tjr sinon tout à l'air ok
                                0
                                1. euh commen on lance les mise a jour windows stp??
                                  0
                                  1. outils -> windows update

                                    ou dans démarrer tous les programme il doit y etre en haut du menu
                                    0
                                    1. normalemen oui mai je viens de le refair.
                                      je doi refaire un rapport hijackthis pour confirmé?
                                      0
                                      Précédent
                                      • 1
                                      • 2
                                      • 3
                                      • 4