Soucis virus Balge... je crois - Page 3

Précédent
  • 1
  • 2
  • 3
cocoblacl Messages postés 19 Statut Membre
 
Voici mon rapport,

--------------------\\ Lop S&D 4.2.4-4 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-58 )
BIOS : EPP runtime BIOS - Version 1.1
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.7.1098 [VPS 080922-0] 4.7.1098 (Activated)
Firewall : Norton Internet Security 2007 (Activated)
C:\ (Local Disk) - NTFS - Total : 100 Go Free : 67 Go
D:\ (CD or DVD)
E:\ (Local Disk) - NTFS - Total : 10 Go Free : 10 Go

"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 22/09/2008|23:07 )

--------------------\\ Listing des dossiers dans APPLIC~1

[06/07/2008|17:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[09/08/2008|14:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\ArcSoft
[10/05/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\ATI
[09/08/2008|14:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Canon
[20/09/2008|19:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[20/08/2008|19:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\HPAppData
[10/05/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\hpqLog
[10/05/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[10/05/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
[07/09/2008|00:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\InterVideo
[12/05/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[21/09/2008|09:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[22/09/2008|21:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft Web Folders
[29/08/2008|09:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[21/08/2008|11:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nokia
[21/08/2008|11:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Suite
[10/05/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
[09/08/2008|14:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\ScanSoft
[16/09/2008|22:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[16/09/2008|20:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\skypePM
[10/05/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[16/09/2008|20:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\VoipCheapCom
[23/08/2008|18:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
[31/08/2008|15:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Yahoo!

[10/05/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{623D32E9-0C62-4453-AD44-98B31F52A5E1}
[05/06/2008|21:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[21/08/2008|11:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[10/05/2008|01:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[10/05/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[20/08/2008|19:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[20/08/2008|19:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP Product Assistant
[20/08/2008|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[10/05/2008|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[04/06/2008|21:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
[21/09/2008|09:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[21/08/2008|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[10/09/2008|21:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[21/08/2008|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[10/05/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Roxio
[10/05/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[09/08/2008|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[22/05/2008|20:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[10/05/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[02/09/2008|22:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[23/08/2008|18:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[12/05/2008|23:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[03/06/2008|20:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\hpqLog
[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\InstallShield
[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[10/05/2008|09:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun

[23/08/2008|18:03] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[10/05/2008|09:43] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[08/09/2008 20:53][--a------] C:\WINDOWS\tasks\Norton Internet Security - Analyse systŠme complŠte - Administrateur.job
[22/09/2008 22:54][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 10:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[10/05/2008|09:43] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[06/09/2008|22:01] C:\Program Files\Adobe
[20/09/2008|19:04] C:\Program Files\Alwil Software
[10/05/2008|09:43] C:\Program Files\Analog Devices
[09/08/2008|14:36] C:\Program Files\ArcSoft
[10/05/2008|09:43] C:\Program Files\ATI Technologies
[23/07/2008|18:25] C:\Program Files\Business Objects
[09/08/2008|14:35] C:\Program Files\Canon
[09/08/2008|14:34] C:\Program Files\CanonBJ
[10/05/2008|09:43] C:\Program Files\ComPlus Applications
[21/08/2008|11:32] C:\Program Files\DIFX
[23/07/2008|19:54] C:\Program Files\EasyPHP 2.0b1
[20/09/2008|12:27] C:\Program Files\eMule
[21/09/2008|09:15] C:\Program Files\Fichiers communs
[10/05/2008|09:43] C:\Program Files\Fingerprint Sensor
[22/05/2008|19:22] C:\Program Files\Google
[20/08/2008|19:27] C:\Program Files\Hewlett-Packard
[20/08/2008|19:28] C:\Program Files\HP
[10/05/2008|00:48] C:\Program Files\HPQ
[09/08/2008|14:40] C:\Program Files\InstallShield Installation Information
[21/08/2008|09:22] C:\Program Files\Internet Explorer
[10/05/2008|00:59] C:\Program Files\InterVideo
[23/08/2008|17:27] C:\Program Files\Java
[10/05/2008|01:00] C:\Program Files\Macrovision Corp
[22/09/2008|22:58] C:\Program Files\Malwarebytes' Anti-Malware
[21/08/2008|09:32] C:\Program Files\Messenger
[14/05/2008|00:30] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[06/07/2008|16:29] C:\Program Files\microsoft frontpage
[06/07/2008|16:30] C:\Program Files\Microsoft Office
[12/05/2008|23:19] C:\Program Files\Microsoft SQL Server Compact Edition
[10/05/2008|09:44] C:\Program Files\Microsoft Visual Studio
[10/05/2008|09:44] C:\Program Files\Microsoft Works
[10/05/2008|09:44] C:\Program Files\Microsoft.NET
[10/05/2008|09:44] C:\Program Files\Movie Maker
[22/09/2008|23:01] C:\Program Files\Mozilla Firefox
[10/05/2008|09:44] C:\Program Files\MSN
[10/05/2008|09:44] C:\Program Files\MSN Gaming Zone
[10/05/2008|09:44] C:\Program Files\MSXML 4.0
[14/05/2008|00:30] C:\Program Files\MSXML 6.0
[10/05/2008|09:44] C:\Program Files\NetMeeting
[09/08/2008|14:40] C:\Program Files\NewSoft
[21/08/2008|11:32] C:\Program Files\Nokia
[06/07/2008|20:13] C:\Program Files\Norton Internet Security
[10/05/2008|09:44] C:\Program Files\Online Services
[14/05/2008|00:30] C:\Program Files\Outlook Express
[21/08/2008|11:32] C:\Program Files\PC Connectivity Solution
[10/05/2008|00:55] C:\Program Files\Raccourcis de programmes
[10/05/2008|09:44] C:\Program Files\Roxio
[06/07/2008|16:58] C:\Program Files\SAGEM
[09/08/2008|14:38] C:\Program Files\ScanSoft
[10/05/2008|09:44] C:\Program Files\Services en ligne
[22/05/2008|20:24] C:\Program Files\Skype
[03/06/2008|23:57] C:\Program Files\Sun
[06/07/2008|20:05] C:\Program Files\Symantec
[10/05/2008|09:44] C:\Program Files\Synaptics
[15/09/2008|22:49] C:\Program Files\Trend Micro
[10/05/2008|09:44] C:\Program Files\Uninstall Information
[02/09/2008|22:56] C:\Program Files\VoipCheapCom
[10/05/2008|01:03] C:\Program Files\WIDCOMM
[18/05/2008|22:56] C:\Program Files\Windows Live
[10/05/2008|09:44] C:\Program Files\Windows Media Connect 2
[10/05/2008|09:44] C:\Program Files\Windows Media Player
[10/05/2008|09:44] C:\Program Files\Windows NT
[10/05/2008|09:44] C:\Program Files\WindowsUpdate
[23/08/2008|18:01] C:\Program Files\WinRAR
[10/05/2008|09:44] C:\Program Files\xerox
[22/09/2008|22:59] C:\Program Files\Yahoo!

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[06/07/2008|17:41] C:\Program Files\Fichiers communs\Adobe
[23/07/2008|18:25] C:\Program Files\Fichiers communs\Business Objects
[09/08/2008|14:35] C:\Program Files\Fichiers communs\CANON
[10/05/2008|09:43] C:\Program Files\Fichiers communs\DESIGNER
[20/08/2008|19:23] C:\Program Files\Fichiers communs\Hewlett-Packard
[20/08/2008|19:24] C:\Program Files\Fichiers communs\HP
[10/05/2008|01:00] C:\Program Files\Fichiers communs\InstallShield
[10/05/2008|00:59] C:\Program Files\Fichiers communs\InterVideo
[10/05/2008|09:43] C:\Program Files\Fichiers communs\Java
[10/05/2008|09:43] C:\Program Files\Fichiers communs\LightScribe
[24/08/2008|10:51] C:\Program Files\Fichiers communs\Microsoft Shared
[10/05/2008|09:43] C:\Program Files\Fichiers communs\MSSoap
[09/08/2008|14:41] C:\Program Files\Fichiers communs\NewSoft
[21/08/2008|11:32] C:\Program Files\Fichiers communs\Nokia
[10/05/2008|09:43] C:\Program Files\Fichiers communs\ODBC
[21/08/2008|11:33] C:\Program Files\Fichiers communs\PCSuite
[09/08/2008|14:40] C:\Program Files\Fichiers communs\PDFView
[10/05/2008|09:43] C:\Program Files\Fichiers communs\Roxio Shared
[09/08/2008|14:39] C:\Program Files\Fichiers communs\ScanSoft Shared
[10/05/2008|09:43] C:\Program Files\Fichiers communs\Services
[22/05/2008|20:24] C:\Program Files\Fichiers communs\Skype
[10/05/2008|09:43] C:\Program Files\Fichiers communs\Sonic Shared
[10/05/2008|09:43] C:\Program Files\Fichiers communs\SpeechEngines
[10/05/2008|09:43] C:\Program Files\Fichiers communs\SureThing Shared
[17/09/2008|21:25] C:\Program Files\Fichiers communs\Symantec Shared
[06/07/2008|16:33] C:\Program Files\Fichiers communs\System
[12/05/2008|23:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 64 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ADMINI~1\Cookies\administrateur@advertising[2].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-22 23:08:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

[F:14][D:6]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
[F:43][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:32][D:4]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/09/2008|23:09 - Option : [1]

--------------------\\ Fin du rapport a 23:09:05

j'ai réinstallé avast et il fonctionne maintenant
0
geoffrey5 Messages postés 14008 Statut Contributeur sécurité 10
 
ok maintenant :

▶ Relance Lop S&D

▶ Choisis cette fois-ci l'option 2 (Suppression)

▶ Ne ferme pas la fenêtre lors de la suppression !

▶ Poste le rapport généré (C:\lopR.txt)

* (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
0
geoffrey5 Messages postés 14008 Statut Contributeur sécurité 10
 
ensuite :

▶ Télécharge OTMoveIt (de Old_Timer) sur ton Bureau

(c est le numéro 7 en bas de la page)

▶ Double-clique sur OTMoveIt.exe pour le lancer.
▶ Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.
▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.

C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo\HiLoKeyGenerator.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo\HiLoKeyGeneratorFactory.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo\HiLoKeyGeneratorFactoryMBean.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGenerator.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGeneratorFactory.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGeneratorFactoryService.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGeneratorFactoryServiceMBean.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo\HiLoKeyGenerator.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo\HiLoKeyGeneratorFactory.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\hilo\HiLoKeyGeneratorFactoryMBean.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGenerator.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGeneratorFactory.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGeneratorFactoryService.class
C:\Documents and Settings\Administrateur\Bureau\OPEN SOURCE\PENTAHO\pentaho_demo_hsqldb-1.7.0.RC1\pentaho-demo\jboss\server\default\deploy\uuid-key-generator.sar\org\jboss\ejb\plugins\keygenerator\uuid\UUIDKeyGeneratorFactoryServiceMBean.class


▶ clique sur MoveIt! pour lancer la suppression.
▶ Le résultat apparaitra dans le cadre "Results".
▶ Clique sur Exit pour fermer.
▶ Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

▶Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

ensuite redémarre le pc et refais un nouveau rapport hijackthis stp
0
Précédent
  • 1
  • 2
  • 3