Fichiers caché
http://img222.imageshack.us/img222/1074/cach.jpg
merci d'avance
Configuration: Windows Vista Firefox 3.0.7 HD4870 core 2 duo E6550 4Go de Ram ddr2 800mhz
26 réponses
Un virus a rendu les fichiers du disque dur externe invisibles, et après sa suppression, l’utilisateur fait face à des fichiers marqués comme cachés sur Windows Vista. Des réponses préconisent des outils de sécurité comme RSIT et HijackThis pour diagnostiquer les infections et récupérer les logs utiles, notamment log.txt et info.txt. L’outline des procédures inclut le téléchargement et l’exécution de RSIT, la collecte des informations système et la remise des rapports dans le dossier C:\rsit pour analyse. En complément, l’ensemble des éléments affichés dans les logs, notamment les programmes désinstallés et les détails d’authentification, peut aider à évaluer l’impact réel et les actions à prévoir.
-
Contributeur sécuritéutilise pour supprimer tes traces
CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo
(dans les options puis avancé :désactive la case: effacer les fichiers de plus de 48 heures)
https://www.malekal.com/tutoriel-ccleaner/
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
-----------------------
remets un rapport RSIt -
========== FILES ==========
File/Folder C:\Windows\system32\xxyvvsrO.dll not found.
File/Folder C:\Windows\system32\cbXPjjHX.dll not found.
File/Folder C:\Windows\system32\cbXRLeEx.dll not found.
File/Folder C:\Windows\SysWow64\qoMeDtuT.dll not found.
File/Folder C:\\Windows\\system32\\xxyvvsrO not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks not found.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03212009_143212
############################## [ FindyKill V4.720 ]
# User : ABduX (Administrateurs) # PC-DE-ABDUX
# Update on 19/03/09 by Chiquitine29
# Start at: 14:34:16 | 21/03/2009
# Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz
# Microsoft® Windows Vista™ Édition Intégrale (6.0.6001 64-bit) # Service Pack 1
# Internet Explorer 7.0.6001.18000
# Windows Firewall Status : Disabled
# AV : Kaspersky Internet Security 7.0.0.125 [ (!) Disabled | Updated ]
# FW : Kaspersky Internet Security[ Enabled ]7.0.0.125
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 41,69 Go (14,81 Go free) # NTFS
# D:\ # Disque fixe local # 107,34 Go (1,19 Go free) # NTFS
# E:\ # Disque fixe local # 149,05 Go (1,89 Go free) [ABduX] # NTFS
# G:\ # Disque CD-ROM
############################## [ Processus actifs ]
D:\Windows.old\Program Files\BitLord\BitLord.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe
C:\Program Files (x86)\Google\Google Talk\googletalk.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\MessengerDiscovery\MessengerDiscovery Live.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
################## [ Fichiers / Dossiers infectieux C:\ ]
################## [ C:\Windows ]
################## [ C:\Windows\system32 ]
################## [ C:\Windows\system32\drivers ]
################## [ C:\.. Application Data ... ]
################## [ Registre / Clés infectieuses ]
################## [ Recherche dans supports amovibles]
# Presence des fichiers :
################## [ Registre / Mountpoint2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.720 ! ] -
Contributeur sécuritédouble-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
:files
C:\Windows\system32\xxyvvsrO.dll
C:\Windows\system32\cbXPjjHX.dll
C:\Windows\system32\cbXRLeEx.dll
C:\Windows\SysWow64\qoMeDtuT.dll
C:\\Windows\\system32\\xxyvvsrO
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
____________________________
Telecharge FindyKill sur ton bureau :
--> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe
--> Lance l installation avec les parametres par default
--> Double clic sur le raccourci FindyKill sur ton bureau
--> Au menu principal,choisi l option 1 (Recherche)
--> Post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque -
comme la derniere fois votre ordinateur est sain
-
Contributeur sécuritéTélécharge RavAntivirus d'Evosla :
http://ww25.evosla.com/compteur.php?soft=rav_antivirus
# Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
# Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
# Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
# Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
# Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
# Retire tes disques amovibles et redémarrez votre ordinateur.
# Poste le rapport, si infection!
2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
Double-clique sur l’icône.
Les icônes vont disparaître. C’est normal.
Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
Redémarre ensuite le PC. -
là je ne vois meme plus les fichiers je ne peux les voir qu'avec winrar :s c'est trop bizzar tout ça
-
Contributeur sécuritéessaye sur les fichiers en quaestion de cliquer avec le bouton droit de la souris puis tu choisi proritété puis PARTAGE puis décoche caché et dans PARTAGE décoche rendre le dossier confidentiel
-
alors ya pa de solution ?
-
euh je peux changer tout les fichier sof ces fichiers qui ont était touché par le virus
-
Contributeur sécuritésous vista 64 combofix ne marche pas c'est bien dommage!
essaye de reparer vista:
http://www.vista-xp.fr/forum/topic428.html -
euuh kaspersky a enlevé tous les virus le seul problème c'est que je ne peux pas rendre les fishier en mode normal on dirait des fichiers system on ne peux leur enlevé le mode cacher
-
Contributeur sécuriténettoie ton ordi avec ccleaner et regcleaner
https://www.malekal.com/tutoriel-ccleaner/
https://www.malekal.com/nettoyer-sa-base-de-registre-avec-windows-registry-cleaner/
_____________
lance tool cleaner pour virer ce qui a été utilisé
http://www.commentcamarche.net/telecharger/logiciel 39 antivirus
_____________
encore des soucis? kaspersky trouve des infections?? -
Logfile of random's system information tool 1.05 (written by random/random)
Run by ABduX at 2009-03-16 12:36:47
Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
System drive C: has 13 GB (31%) free of 43 GB
Total RAM: 4094 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:50, on 16/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
D:\Windows.old\Program Files\BitLord\BitLord.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Users\ABduX\AppData\Local\eSupport.com\driveragent_270.exe
C:\Program Files (x86)\Frigate3\Frigate3.exe
E:\Steam\Steam.exe
E:\SBReV\SBReV.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\ABduX\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\ABduX.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files (x86)\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BitComet] "D:\Windows.old\Program Files\BitLord\BitLord.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MI1933~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{45968CB4-5885-48B3-BFCF-A278BB7EF597}: NameServer = 192.168.10.31
O17 - HKLM\System\CS1\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O17 - HKLM\System\CS2\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
-
Contributeur sécuritéremets un rapport RSIt
-
========== FILES ==========
File/Folder F:\lkwh.cmd not found.
File/Folder C:\Windows\SysWow64\qoMeDtuT.dll not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks not found.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}\\ deleted successfully.
========== COMMANDS ==========
File delete failed. C:\Users\ABduX\AppData\Local\Temp\etilqs_78OTACeecc7fR7GAv6A3 scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee-journal scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\Windows\temp\cch~20f631620.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~20f632c99.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~2100548e6.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~210056059.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~2122be281.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~2122bfa07.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~212317e08.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21231a243.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21521c112.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21521d7d0.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21523134a.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~2152329b3.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~215252393.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~215253a97.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21525b32b.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21525c993.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~215266569.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~215267c1b.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21527cf4a.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21527f092.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21528c38b.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~21528d9ec.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~2152ae78e.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~2152b096f.htp scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\OfflineCache\index.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03152009_161209
Files moved on Reboot...
File C:\Users\ABduX\AppData\Local\Temp\etilqs_78OTACeecc7fR7GAv6A3 not found!
File C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee not found!
File C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee-journal not found!
C:\Users\ABduX\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File C:\Windows\temp\cch~20f631620.htp not found!
File C:\Windows\temp\cch~20f632c99.htp not found!
File C:\Windows\temp\cch~2100548e6.htp not found!
File C:\Windows\temp\cch~210056059.htp not found!
File C:\Windows\temp\cch~2122be281.htp not found!
File C:\Windows\temp\cch~2122bfa07.htp not found!
File C:\Windows\temp\cch~212317e08.htp not found!
File C:\Windows\temp\cch~21231a243.htp not found!
File C:\Windows\temp\cch~21521c112.htp not found!
File C:\Windows\temp\cch~21521d7d0.htp not found!
File C:\Windows\temp\cch~21523134a.htp not found!
File C:\Windows\temp\cch~2152329b3.htp not found!
File C:\Windows\temp\cch~215252393.htp not found!
File C:\Windows\temp\cch~215253a97.htp not found!
File C:\Windows\temp\cch~21525b32b.htp not found!
File C:\Windows\temp\cch~21525c993.htp not found!
File C:\Windows\temp\cch~215266569.htp not found!
File C:\Windows\temp\cch~215267c1b.htp not found!
File C:\Windows\temp\cch~21527cf4a.htp not found!
File C:\Windows\temp\cch~21527f092.htp not found!
File C:\Windows\temp\cch~21528c38b.htp not found!
File C:\Windows\temp\cch~21528d9ec.htp not found!
File C:\Windows\temp\cch~2152ae78e.htp not found!
File C:\Windows\temp\cch~2152b096f.htp not found!
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\OfflineCache\index.sqlite moved successfully.
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_001_ moved successfully.
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_002_ moved successfully.
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_003_ moved successfully.
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\urlclassifier3.sqlite moved successfully.
C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\XUL.mfl moved successfully. -
Contributeur sécuritéok branche le disque F
puis
télécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
(attention bien mettre :files)
:files
F:\lkwh.cmd
C:\Windows\SysWow64\qoMeDtuT.dll
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}]
:commands
[purity]
[emptytemp]
[start explorer]
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes. -
http://img502.imageshack.us/img502/9899/erreurs.jpg
voici une foto de l'erreur que jai quand je lance le premier truc en fesant ce que vous mavez demandé
2:
votre ordinateur est sain -
Contributeur sécuritéPour fusionner:
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
_______________
telecharge combofix:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Sauvegarde le sur ton bureau et pas ailleurs !
_________________
branche le disqpue F
puis
Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
File::
F:\lkwh.cmd
C:\Windows\SysWow64\qoMeDtuT.dll
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}]
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
__________
Télécharge RavAntivirus d'Evosla :
http://ww25.evosla.com/compteur.php?soft=rav_antivirus
# Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
# Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
# Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
# Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
# Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
# Retire tes disques amovibles et redémarrez votre ordinateur.
# Poste le rapport, si infection!
2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
Double-clique sur l’icône.
Les icônes vont disparaître. C’est normal.
Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
Redémarre ensuite le PC. -
========== FILES ==========
DllUnregisterServer procedure not found in C:\Windows\system32\xxyvvsrO.dll
C:\Windows\system32\xxyvvsrO.dll NOT unregistered.
C:\Windows\system32\xxyvvsrO.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\system32\cbXPjjHX.dll
C:\Windows\system32\cbXPjjHX.dll NOT unregistered.
C:\Windows\system32\cbXPjjHX.dll moved successfully.
DllUnregisterServer procedure not found in C:\Windows\system32\cbXRLeEx.dll
C:\Windows\system32\cbXRLeEx.dll NOT unregistered.
C:\Windows\system32\cbXRLeEx.dll moved successfully.
File/Folder F:\lkwh.cmd not found.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}\\ not found.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_082348
RSIT :
log :
Logfile of random's system information tool 1.05 (written by random/random)
Run by ABduX at 2009-03-13 21:37:46
Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
System drive C: has 17 GB (40%) free of 43 GB
Total RAM: 4094 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:31, on 13/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
D:\Windows.old\Program Files\BitLord\BitLord.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
E:\Program Files\Steam\steam.exe
C:\Program Files (x86)\Hamachi\hamachi.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\ABduX\Documents\Downloads\Programs\RSIT.exe
C:\Program Files (x86)\trend micro\ABduX.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files (x86)\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BitComet] "D:\Windows.old\Program Files\BitLord\BitLord.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MI1933~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O17 - HKLM\System\CCS\Services\Tcpip\..\{45968CB4-5885-48B3-BFCF-A278BB7EF597}: NameServer = 192.168.10.31
O17 - HKLM\System\CS1\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O17 - HKLM\System\CS2\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O17 - HKLM\System\CS13\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
-
Contributeur sécuritévire ce qui est dans moved files en allant dans poste de travail puis C puis otmovit
_______________
remets un rapport RSIT
- 1
- 2