7 virus!!help please - Page 4

  1. lol sinno fait le demain ^^
    0
    1. ben je croi ke je vai faire ca oui mai bon....
      ben je te di la suite demain soir si je peu o pire la semaine...lol
      merci encore pour tou
      0
      1. oué toute facon je sais si y a une réponse donc tkt pas.
        0
        1. hello!
          ben c bon tou est nikel aparamen sur le pc...
          et il ma demander de regarder son pc fixe....lol
          g pa encore regarder mai je pense demain soir je regarderai....je mettrai antivir et ccleaner ainsi ke
          hijackthis... je refrai une nouvelle discution ou on peu continué sur celle ci?
          enfin si t dacord bien sur....lol
          merci pour tout
          0
          1. oué tu peux continuer ici
            0
            1. hello, ben jui pa mal occupé c jour ci mai lundi normalmen je pourrai me lancé sur le pc fix
              voir skil a...enfin faire d rapport antivirus, hijackthis et pi un ti cou de ccleaner tan k faire...
              lol
              merci a lundi
              0
              1. hello!!
                ca y est jui de retour enfin!
                dsl javai di lundi mai c la fin de mon stage alors jui a fond sur mon rapport et mon power point...
                enfin donc voila g scanné le burotik de mon oncle....
                tu va rire...je te laisse lire tou ca c maran antivir en a trouvé 6 ke g mi en karantaine!

                antivir:

                Avira AntiVir Personal
                Report file date: mercredi 4 juin 2008 19:44

                Scanning for 1165085 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 2) [5.1.2600]
                Boot mode: Normally booted
                Username: SYSTEM
                Computer name: XPSP2-8DBCC1C1C

                Version information:
                BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
                AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
                AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
                LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
                LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
                ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 21/03/2008 19:12:34
                ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 25/03/2008 08:27:50
                Engineversion : 8.1.0.28
                AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                AESCRIPT.DLL : 8.1.0.19 229754 Bytes 07/04/2008 15:34:44
                AESCN.DLL : 8.1.0.12 115060 Bytes 07/04/2008 15:34:44
                AERDL.DLL : 8.1.0.19 418164 Bytes 07/04/2008 15:34:44
                AEPACK.DLL : 8.1.1.0 364918 Bytes 18/03/2008 11:20:42
                AEOFFICE.DLL : 8.1.0.15 192889 Bytes 07/04/2008 15:34:44
                AEHEUR.DLL : 8.1.0.15 1147253 Bytes 07/04/2008 15:34:44
                AEHELP.DLL : 8.1.0.11 115061 Bytes 07/04/2008 15:34:43
                AEGEN.DLL : 8.1.0.15 299379 Bytes 07/04/2008 15:34:43
                AEEMU.DLL : 8.1.0.5 430450 Bytes 07/04/2008 15:34:43
                AECORE.DLL : 8.1.0.25 168309 Bytes 08/04/2008 09:58:32
                AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
                AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
                AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
                RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: on
                Scan boot sector.................: on
                Boot sectors.....................: C:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: mercredi 4 juin 2008 19:44

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'raid_tool.exe' - '1' Module(s) have been scanned
                Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                Scan process 'Residence.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                Scan process 'SonyTray.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
                Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'StyleXP.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
                Scan process 'AsusProb.exe' - '1' Module(s) have been scanned
                Scan process 'SMTray.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'pctsTray.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
                Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
                Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
                Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'StyleXPService.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                39 processes with 39 modules were scanned

                Starting master boot sector scan:
                Master boot sector HD0
                [INFO] No virus was found!

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '33' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\SAUVEGARDEPCCHEF\[NTFS]\Documents and Settings\dominique\Mes documents\Mes fichiers reçus\MsgPlus-301(1).exe
                [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.AG.2
                [NOTE] The file was moved to '48add7c0.qua'!
                C:\SAUVEGARDEPCCHEF\[NTFS]\Documents and Settings\dominique\Mes documents\Mes fichiers reçus\MsgPlus-301.exe
                [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.AG.2
                [NOTE] The file was moved to '48add7f8.qua'!
                C:\SAUVEGARDEPCCHEF\[NTFS]\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1B2354CF.exe
                [0] Archive type: HIDDEN
                --> FIL\\\?\C:\SAUVEGARDEPCCHEF\[NTFS]\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1B2354CF.exe
                [DETECTION] Contains detection pattern of the worm WORM/Korgo.I
                [NOTE] The file was moved to '4878dc25.qua'!
                C:\SAUVEGARDEPCCHEF\[NTFS]\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3AB54011
                [0] Archive type: HIDDEN
                --> FIL\\\?\C:\SAUVEGARDEPCCHEF\[NTFS]\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3AB54011
                [DETECTION] Is the Trojan horse TR/Rootkit.Rand.I.1
                [NOTE] The file was moved to '4888dc67.qua'!
                C:\SAUVEGARDEPCCHEF\[NTFS]\RECYCLER\S-1-5-21-583907252-573735546-839522115-1003\Dc2\dominique.FAMILLE-Y45NWJQ\Local Settings\Temporary Internet Files\Content.IE5\X7N7X94A\pub[1].gif
                [DETECTION] Is the Trojan horse TR/Dropper.Gen
                [NOTE] The file was moved to '48a8dd2b.qua'!
                C:\SAUVEGARDEPCCHEF\[NTFS]\System Volume Information\_restore{EAA43A85-7FD6-4BEE-9F62-5ABB23B125C5}\RP13\A0000586.exe
                [DETECTION] Contains detection pattern of the worm WORM/Korgo.I
                [NOTE] The file was moved to '4876dd05.qua'!

                End of the scan: mercredi 4 juin 2008 20:27
                Used time: 43:02 min

                The scan has been done completely.

                7313 Scanning directories
                346415 Files were scanned
                6 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                6 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                346409 Files not concerned
                4205 Archives were scanned
                1 Warnings
                6 Notes

                hijackthis:
                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 19:19:40, on 04/06/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Spyware Doctor\pctsAuxs.exe
                C:\Program Files\Spyware Doctor\pctsSvc.exe
                C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                C:\Program Files\ASUS\Probe\AsusProb.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\Program Files\Spyware Doctor\pctsTray.exe
                C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
                C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
                C:\Program Files\VIA\RAID\raid_tool.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\WINDOWS\System32\alg.exe
                C:\HiJackThis.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                O4 - Global Startup: Picture Package Menu.lnk = ?
                O4 - Global Startup: Picture Package VCD Maker.lnk = ?
                O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe (file missing)
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe (file missing)
                O23 - Service: Trend Micro Personal Firewall (TmPfw) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe (file missing)
                O23 - Service: Trend Micro Proxy Service (tmproxy) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe (file missing)
                0
                Précédent
                • 1
                • 2
                • 3
                • 4