Virus dans mon pc

Bonjour,

au secour .j'ai besoin d'aide mon pc est atteint svp aider moi.
Configuration: Windows XP
Internet Explorer 6.0

6 réponses

  1. Contributeur
    Bonjour !

    Télécharges hijackthis : http://www.trendsecure.com/portal/en-US/_download/HiJackThis.zip

    et voici un gif pour bien l'installer : http://pageperso.aol.fr/balltrap34/Hijenr.gif

    - Une fois téléchargé, renommer l'éxécutable en HJT.exe pour contrer une éventuelle infection vundo
    - Double-clic dessus
    - Clic sur "Do a system scan and save the log"
    - Copies le rapport, le coller dans la réponse
    0
    1. Contributeur sécurité
      Bonjour

      Il est atteint ?
      Par quoi ? La vieillesse, la maladie, la rouille ?

      Comment veux-tu recevoir de l'aide en posant une telle question ?

      Décris ce qui se passe, depuis combien de temps, ce que tu as fait...

      Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

      http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

      * Enregistre HJTInstall.exe sur ton bureau.

      * Double-clique sur HJTInstall.exe pour lancer le programme

      Tuto : https://www.malekal.com/tutoriel-hijackthis/
      http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
      http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

      * Accepte la license en cliquant sur le bouton "I Accept"
      * Choisis l'option "Do a system scan and save a log file"
      * Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
      * Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

      * Colle le rapport que tu viens de copier sur ce forum
      0
      1. il est atteint de virus *tup flirt* cé virus avc des image qui apparait n'import quand.
        ya 1 chose je n'ai encors rien fait comme je miy connait pas trop en informatique
        0
        1. voila le rapport

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:33:07, on 08/11/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.update.microsoft.com/windowsupdate/v6/default.aspx?ln=fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
          O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O17 - HKLM\System\CCS\Services\Tcpip\..\{FD80387C-3F00-45A4-97F1-161A26AB6C81}: NameServer = 208.67.222.222 193.55.10.102
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          0
          1. Contributeur
            Ta version d'Xp n'est pas officielle ?

            Bon ce qu'on va faire en premier lieu, Tu vas télécharger la dernière version de Malwarebytes anti malware 1.30 : https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

            Voici un tuto pour bien l'installer et l'utiliser : http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
            (N'utilises pas File assassin)
            <gras>

            N'oublie pas de supprimer les menaces à la fin du scan et de poster le log sur le forum !

            >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

            Si tu as utilisé des cléfs USb ou disques durs externes récemment, télécharge ceci : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

            Et ne l'utilise pas pour le moment !

            Pour finir sache que sans version offcicielle tu sera toujours plus vulnérable
            A+
            0
            1. bonjour.
              et voila le rapport

              Malwarebytes' Anti-Malware 1.30
              Version de la base de données: 1375
              Windows 5.1.2600 Service Pack 2

              09/11/2008 09:18:46
              mbam-log-2008-11-09 (09-18-46).txt

              Type de recherche: Examen rapide
              Eléments examinés: 42895
              Temps écoulé: 7 minute(s), 13 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 1
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 1
              Elément(s) de données du Registre infecté(s): 2
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 8

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              C:\WINDOWS\system32\ckvo1.dll (Trojan.Agent) -> Delete on reboot.

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kamsoft (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\Documents and Settings\USER\Local Settings\Application Data\sfkekp_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
              C:\Documents and Settings\USER\Local Settings\Application Data\sfkekp_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
              C:\Documents and Settings\USER\Local Settings\Application Data\sfkekp.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
              C:\Documents and Settings\USER\Local Settings\Application Data\sfkekp.exe (Adware.Navipromo.H) -> Delete on reboot.
              C:\WINDOWS\system32\ckvo.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\ckvo0.dll (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\ckvo1.dll (Trojan.Agent) -> Delete on reboot.
              C:\xih9.cmd (Trojan.Agent) -> Quarantined and deleted successfully.
              0
              1. Contributeur
                Bien ! avais tu utilisé des clefs USB récemment alors ?
                0