Problème de virus et d'antivirus

Fermé
nopelio - 29 août 2008 à 11:42
 nopelio - 29 août 2008 à 14:25
Bonjour, J'ai installé avast sur mon pc comme antivirus depuis que je l'ai reformaté (presque 2 mois) et suite a un téléchargement d'un albuml sur internet il détecte la présence d'un virus.Donc la j'ai lancé un scan et la il s'averait qu'il y'avait plusieurs virus. Du coup je lui demande de supprimer tous les virus mais impossible d'en supprimer quelques un d'entre eux. En meme temps je vois le message "You have a security problem" dans la barre des taches je clique dessus et ca me propose un antivirus, celui de windows : Antivirus XP 2008. seul probleme il est payant!! Donc j'essaie de le desinstaller mais impossible d'y arriver, quand je clique sur le fichier uninstall une fenetre d'erreur apparait avec "lenvoyer le rapport d'erreurs" ou "ne pas envoyer".
Je retourne sur internet esperant trouver un antivirus capable de supprimer tous les virus sur mon ordinateur et je tombe sur "Antivirus 2009" croyant que celui-ci n'étant pas payant...et baah si il était payant aussi et la je me retrouve face au meme probleme qu'avant je ne peux pas le supprimer.
Après quelques rapides recherches sur la toile ce matin je découvre le logiciel Hijackthis, je le télecharge et voici le rapport de son scan.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:26, on 29/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\lphc5v9j0egag.exe
C:\WINDOWS\system32\sysrest32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\DOCUME~1\ADMINI~1.TIT\LOCALS~1\Temp\5.tmp.exe
C:\Program Files\Sitecom\Sitecom WL-171 Wireless LAN Card\Installer\WLANUTL.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\DOCUME~1\ADMINI~1.TIT\LOCALS~1\Temp\c.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
G:\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: &Research - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\WINDOWS\system32\winsrc.dll
O2 - BHO: CableRouting module - {18CB1A7B-94CD-4582-8022-ADA16851E44B} - C:\Documents and Settings\All Users.WINDOWS\Application Data\services\services.dll
O2 - BHO: msvbcr40 module - {2756BAD7-2F9F-47ef-AE6D-8D39CCEB396F} - C:\WINDOWS\system32\msvbcr40.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [lphc5v9j0egag] C:\WINDOWS\system32\lphc5v9j0egag.exe
O4 - HKLM\..\Run: [SMrhc1v9j0egag] C:\Program Files\rhc1v9j0egag\rhc1v9j0egag.exe
O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\ADMINI~1.TIT\LOCALS~1\Temp\5.tmp.exe
O4 - HKCU\..\Run: [84126827630404073879635405696895] C:\Program Files\AV9\av2009.exe
O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\ieupdates.exe"
O4 - HKCU\..\Run: [s9201] "C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\av2008xp.exe" /autorun
O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom WL-171 Wireless LAN Card\Installer\WLANUTL.exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
A voir également:

6 réponses

Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 295
29 août 2008 à 11:45
Salut,

---> Fais un scan rapide avec MBAM, supprime tout ce qu'il trouve et poste le rapport :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
0
Ok je lance le rapport maintenant je te le poste dès que j'a'i fini.
0
ca y'est le scan est terminé avec malwarebytes. j'ai supprimé les virus détectés.voici le rapport:

Malwarebytes' Anti-Malware 1.25
Version de la base de données: 1094
Windows 5.1.2600 Service Pack 2

14:16:44 29/08/2008
mbam-log-08-29-2008 (14-16-33).txt

Type de recherche: Examen complet (C:\|F:\|)
Eléments examinés: 82212
Temps écoulé: 1 hour(s), 33 minute(s), 8 second(s)

Processus mémoire infecté(s): 2
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 23
Valeur(s) du Registre infectée(s): 12
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 22
Fichier(s) infecté(s): 51

Processus mémoire infecté(s):
C:\WINDOWS\system32\lphc5v9j0egag.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\sysrest32.exe (Rootkit.Agent) -> No action taken.

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\blphc5v9j0egag.scr (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\msvbcr40.dll (Trojan.BHO) -> No action taken.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\cablerouting.cablerouting (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8b8df25f-2c47-4473-8e1c-7f54ac7ef481} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{18cb1a7b-94cd-4582-8022-ada16851e44b} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18cb1a7b-94cd-4582-8022-ada16851e44b} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\cablerouting.cablerouting.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\msvbcr40.msvbcr40 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2756bad7-2f9f-47ef-ae6d-8d39cceb396f} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2756bad7-2f9f-47ef-ae6d-8d39cceb396f} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\msvbcr40.msvbcr40.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328} (Adware.Search Toolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Adware.Search Toolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mxlivemedia (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\antivirus2008y (Rogue.Antivirus2008) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\antivirus2008y (Rogue.Antivirus2008) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SoftLand Ltd (Trojan.FakeAlert) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{2756bad7-2f9f-47ef-ae6d-8d39cceb396f} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smrhc1v9j0egag (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\84126827630404073879635405696895 (Rogue.Antivirus2009) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\s9201 (Rogue.XPAntivirus) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IEUpdate (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysrest32.exe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc5v9j0egag (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Somefox (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> No action taken.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.

Dossier(s) infecté(s):
C:\Program Files\Antivirus2008y (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
C:\Program Files\AV9 (Rogue.Antivirus2009) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\BASE (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\DELETED (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\SAVED (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Antivirus2008y (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Packages (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Menu Démarrer\Antivirus 2009 (Rogue.Antivirus) -> No action taken.

Fichier(s) infecté(s):
C:\WINDOWS\system32\blphc5v9j0egag.scr (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\services\services.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\msvbcr40.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\winsrc.dll (Adware.Search Toolbar) -> No action taken.
C:\WINDOWS\system32\cddapdbambyxgfi.exe (Malware.Trace) -> No action taken.
C:\Program Files\Antivirus2008y\antvrs.exe (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\rhc1v9j0egag\database.dat (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\license.txt (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\MFC71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\MFC71ENU.DLL (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\msvcp71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\msvcr71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\rhc1v9j0egag.exe (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\rhc1v9j0egag.exe.local (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\Uninstall.exe (Rogue.Multiple) -> No action taken.
C:\Program Files\AV9\av2009.exe (Rogue.Antivirus2009) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\av2008xp.exe (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080828100223953.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080828151849593.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080828234322250.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829003447828.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829003935156.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829104913203.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829110642781.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Menu Démarrer\Antivirus 2009\Antivirus 2009.lnk (Rogue.Antivirus) -> No action taken.
C:\WINDOWS\system32\ieupdates.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\sysrest32.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\lphc5v9j0egag.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\phc5v9j0egag.bmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\pphc5v9j0egag.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\5.tmp.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Bureau\Antivirus XP 2008.lnk (Rogue.Antivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Bureau\Antivirus 2009.lnk (Rogue.Antivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt15.tmp (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt5.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt6.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt7.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt8.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt9.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttA.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttB.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttC.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttF.tmp (Trojan.Downloader) -> No action taken.
0
ca y'est le scan est terminé avec malwarebytes. j'ai supprimé les virus détectés.voici le rapport:

Malwarebytes' Anti-Malware 1.25
Version de la base de données: 1094
Windows 5.1.2600 Service Pack 2

14:16:44 29/08/2008
mbam-log-08-29-2008 (14-16-33).txt

Type de recherche: Examen complet (C:\|F:\|)
Eléments examinés: 82212
Temps écoulé: 1 hour(s), 33 minute(s), 8 second(s)

Processus mémoire infecté(s): 2
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 23
Valeur(s) du Registre infectée(s): 12
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 22
Fichier(s) infecté(s): 51

Processus mémoire infecté(s):
C:\WINDOWS\system32\lphc5v9j0egag.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\sysrest32.exe (Rootkit.Agent) -> No action taken.

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\blphc5v9j0egag.scr (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\msvbcr40.dll (Trojan.BHO) -> No action taken.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\cablerouting.cablerouting (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8b8df25f-2c47-4473-8e1c-7f54ac7ef481} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{18cb1a7b-94cd-4582-8022-ada16851e44b} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18cb1a7b-94cd-4582-8022-ada16851e44b} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\cablerouting.cablerouting.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\msvbcr40.msvbcr40 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2756bad7-2f9f-47ef-ae6d-8d39cceb396f} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2756bad7-2f9f-47ef-ae6d-8d39cceb396f} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\msvbcr40.msvbcr40.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328} (Adware.Search Toolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Adware.Search Toolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mxlivemedia (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\antivirus2008y (Rogue.Antivirus2008) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\antivirus2008y (Rogue.Antivirus2008) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SoftLand Ltd (Trojan.FakeAlert) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{2756bad7-2f9f-47ef-ae6d-8d39cceb396f} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smrhc1v9j0egag (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\84126827630404073879635405696895 (Rogue.Antivirus2009) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\s9201 (Rogue.XPAntivirus) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IEUpdate (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysrest32.exe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc5v9j0egag (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Somefox (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> No action taken.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.

Dossier(s) infecté(s):
C:\Program Files\Antivirus2008y (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
C:\Program Files\AV9 (Rogue.Antivirus2009) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\BASE (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\DELETED (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\SAVED (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Antivirus2008y (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\rhc1v9j0egag\Quarantine\Packages (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Menu Démarrer\Antivirus 2009 (Rogue.Antivirus) -> No action taken.

Fichier(s) infecté(s):
C:\WINDOWS\system32\blphc5v9j0egag.scr (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\services\services.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\msvbcr40.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\winsrc.dll (Adware.Search Toolbar) -> No action taken.
C:\WINDOWS\system32\cddapdbambyxgfi.exe (Malware.Trace) -> No action taken.
C:\Program Files\Antivirus2008y\antvrs.exe (Rogue.Antivirus2008) -> No action taken.
C:\Program Files\rhc1v9j0egag\database.dat (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\license.txt (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\MFC71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\MFC71ENU.DLL (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\msvcp71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\msvcr71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\rhc1v9j0egag.exe (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\rhc1v9j0egag.exe.local (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc1v9j0egag\Uninstall.exe (Rogue.Multiple) -> No action taken.
C:\Program Files\AV9\av2009.exe (Rogue.Antivirus2009) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\av2008xp.exe (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080828100223953.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080828151849593.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080828234322250.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829003447828.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829003935156.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829104913203.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080829110642781.log (Rogue.XPAntivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Menu Démarrer\Antivirus 2009\Antivirus 2009.lnk (Rogue.Antivirus) -> No action taken.
C:\WINDOWS\system32\ieupdates.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\sysrest32.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\lphc5v9j0egag.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\phc5v9j0egag.bmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\pphc5v9j0egag.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\5.tmp.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\All Users.WINDOWS\Bureau\Antivirus XP 2008.lnk (Rogue.Antivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Bureau\Antivirus 2009.lnk (Rogue.Antivirus) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt15.tmp (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt5.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt6.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt7.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt8.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.tt9.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttA.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttB.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttC.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrateur.TITANIUM\Local Settings\Temp\.ttF.tmp (Trojan.Downloader) -> No action taken.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 295
29 août 2008 à 14:24
---> Relance MBAM, va dans Quarantaine et supprime tout

---> Désinstalle Avast et installe Antivir (français et bien plus efficace) :
http://dl1.avgate.net/down/windows/antivir_workstation_winu_fr_h.exe

---> Fais un scan complet avec Antivir
0
ok je te tiens au courant. merci
0