Probleme virus, bureau innacessible ....

Résolu
Bonjour,
Je suis de retour mais pas pour mon PC cette fois-ci ...

Donc voici le problème, le bureau de l'ordinateur ne marche plus, on met dessus des fichiers et les fichiers disparaissent, impossible de les retrouver même en recherchant.

Puis avant hier, l'ordinateur ne pouvait plus démarrer, en arrivant sur WINDOWS, il bloquait, on pouvait ouvrir un dossier mais ça prennait 10 min montre en main !!!! ...

Donc, j'ai utilisé le programme Malwarebytes pour détruire les virus, mais maintenant je me dis qu'il faut que je fasse confiance aux expers de ce forum.

Donc voici le rapport de Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:12:37, on 26/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\moi\Mes documents\HiJackThis(2).exe

R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 1744 bytes
Configuration: Windows XP
Firefox 1.5.0.12

12 réponses

  1. Coucou, je suis pas exper, mais le virus, je suis ur y vien d'msn.
    jinvente pas c'est écrit !

    http://www.clubic.com/telecharger-fiche15541-clean-messenger.html

    donc télécharge cleaner messenger.
    avec sa sa ressence tous les probleme et sa tenléve les virus .

    et aussi prend sécuritoo comme entivirus.
    rien de mieux ! je te chercherais un lien ou on peut le télécharger...

    à voila j'ai trouver :

    https://www.nordnet.com/securite
    0
    1. Salut

      désinstal : Kiwee Toolbar2

      renome hijackthis :

      C:\Documents and Settings\moi\Mes documents\HiJackThis(2).exe

      en Monjack

      et refais le scan et post le nouveau rapport stp
      0
      1. Voici le nouveau rapport ...

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:25:36, on 26/07/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\windows\System32\smss.exe
        C:\windows\system32\winlogon.exe
        C:\windows\system32\services.exe
        C:\windows\system32\lsass.exe
        C:\windows\system32\svchost.exe
        C:\windows\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\windows\system32\spoolsv.exe
        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        C:\windows\system32\svchost.exe
        C:\windows\Explorer.EXE
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
        C:\windows\system32\wuauclt.exe
        C:\WINDOWS\system32\msiexec.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Documents and Settings\moi\Mes documents\Monjack.exe

        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        0
        1. Ad-Aware 2007, la version 2008 est sortie

          mais avant d installer la 2008 les ceci :

          https://forum.malekal.com/viewtopic.php?f=45&t=8046

          donc je ne te conseil pas adware

          instal un antivirus :

          Telecharge et instales l'antivirus Antivir Personal Edition Classic :

          ->https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html

          tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59

          internet explorer n est pas a joure (faille de sécurité) telecharge et instal la version 7:

          IE 7 : ftp://ftp.telecharger.com/01net/IE7Setup.exe

          A lire : IE6 VS IE7 : https://forum.malekal.com/viewtopic.php?f=45&t=12405

          instal java : https://sdlc-esd.oracle.com/ESD44/JSCDL/jdk/6u7/jre-6u7-windows-i586-p-s.exe?GroupName=JSC&FilePath=/ESD44/JSCDL/jdk/6u7/jre-6u7-windows-i586-p-s.exe&BHost=javadl.sun.com&File=jre-6u7-windows-i586-p-s.exe&AuthParam=1580978146_46494a57fbc0e7c89e79cfb72e28cd3a&ext=.exe

          tu n as pas de parefeu :

          pare-feu gratuits

          télécharger la version gratuite de Kerio
          Kerio (parefeu)
          https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
          TUTO
          https://kerio.probb.fr/
          SITE de Kerio
          https://kerio.probb.fr/

          ou

          ComodoFirewallPro 2.4 téléchargement
          http://www.personalfirewall.comodo.com/
          Tuto pour la 2.4
          https://infomars.fr/forum/index.php?s=908072e48ff7cf0359366440cb26c93f&showtopic=389
          Tuto pour la 2.4
          http://www.nordicnature.net/tutorials/comodo/cf24wiz.htm
          Attention la 3.0 est en anglais uniquement et est plus difficile a paramétrer
          Tuto pour la 3.0
          https://infomars.fr/forum/index.php?showtopic=1225

          ou

          OnlineArmor :
          téléchargement:https://online-armor-free.fr.softonic.com/

          tutoriels:https://forum.pcastuces.com/sujet.asp?f=25&s=35606
          :https://www.malekal.com/tutorial-online-armor-free/

          reviens sur le forum avec un nouveau rapport hijackthis et dis tes soucis
          0
          1. Voilà tout a été fait et voici un nouveau rapport ....

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 16:45:36, on 26/07/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0011)
            Boot mode: Normal

            Running processes:
            C:\windows\System32\smss.exe
            C:\windows\system32\winlogon.exe
            C:\windows\system32\services.exe
            C:\windows\system32\lsass.exe
            C:\windows\system32\svchost.exe
            C:\windows\System32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            C:\windows\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
            C:\windows\Explorer.EXE
            C:\windows\system32\svchost.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
            C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\windows\system32\wuauclt.exe
            C:\Documents and Settings\moi\Mes documents\Monjack.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
            O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
            O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
            0
            1. parfait

              c est clean y a des soucis ??
              0
              1. Tout est rentré dans l'ordre, le PC lag beaucoup moins, le bureau est accessible ...
                Un vrai travail de pro merci :D
                0
                1. * pour supprimer les outils/fix utilisés :

                  Télécharge ToolsCleaner sur ton bureau.
                  -->
                  ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
                  http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                  http://pc-system.fr/

                  # Clique sur Recherche et laisse le scan agir ...
                  # Clique sur Suppression pour finaliser.
                  # Tu peux, si tu le souhaites, te servir des Options facultatives.
                  # Clique sur Quitter pour obtenir le rapport.
                  # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                  0
                  1. Voici le rapport ...

                    -->- Recherche:

                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
                    C:\Documents and Settings\moi\Mes documents\Clean.zip: trouvé !
                    C:\Documents and Settings\moi\Mes documents\HijackThis.exe: trouvé !
                    C:\Documents and Settings\moi\Mes documents\Clean: trouvé !
                    C:\Program Files\Navilog1: trouvé !
                    C:\Program Files\Navilog1\Navilog1.bat: trouvé !

                    ---------------------------------
                    -->- Suppression:

                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
                    C:\Documents and Settings\moi\Mes documents\Clean.zip: supprimé !
                    C:\Documents and Settings\moi\Mes documents\HijackThis.exe: supprimé !
                    C:\Program Files\Navilog1\Navilog1.bat: supprimé !
                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
                    C:\Documents and Settings\moi\Mes documents\Clean: supprimé !
                    C:\Program Files\Navilog1: supprimé !
                    0
                    1. ok

                      parfait si c est ok met résolu stp

                      @++
                      0
                      1. D'accord !!!
                        Merci encore.
                        Bonne chance pour la suite .....
                        0