Aide Alpha antivirus
Mon ordi est également contaminé par Alpha antivirus, je suis nulle en informatique. Quelqu'un peut-il m'aider ? Merci beaucoup.
Configuration: Windows XP Internet Explorer 7.0
35 réponses
Une personne signale une infection par AlphaAV sur Windows XP et sollicite de l’aide, avec des détails sur le comportement problématique et les outils disponibles. Plusieurs conseils tournent autour de HijackThis pour générer un rapport système et identifier les entrées suspectes, puis des listes d’actions telles que sélectionner des éléments à corriger et relancer l’analyse. D’autres intervenants recommandent des outils complémentaires comme CCleaner et MBAM, la relance de scans, la désactivation puis la réactivation de la restauration système, et la suppression des fichiers d’autorun suspects. En complément, des recommandations portent sur la sécurisation de la navigation et l’ajout d’outils de sécurité comme des extensions de navigateur réputées, afin de prévenir de futures contaminations.
-
Très bien ! Merci pour cette aide précieuse.
Bonne soirée -
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\Doria\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Doria\Bureau\HJTInstall.exe: supprimé !
C:\Documents and Settings\Doria\Bureau\SmitFraudFix.exe: supprimé !
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\Program Files\trend micro\HijackThis\HijackThis.exe: supprimé !
C:\UsbFix.txt: supprimé !
C:\Documents and Settings\Doria\Mes documents\Rsit.exe: supprimé !
C:\Documents and Settings\Doria\Bureau\UsbFix.exe: supprimé !
C:\Documents and Settings\Doria\Bureau\Rsit.exe: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\Program Files\trend micro\HijackThis\hijackthis.log: supprimé !
C:\UsbFix: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\Doria\Bureau\SmitFraudfix: supprimé !
C:\Program Files\trend micro\HijackThis: supprimé !
Normalement, ça a été supprimé ! ;) Si tu vois encore des outils, supprime. Garde MBAM et CCleaner. Passe-les de temps en temps. N'oublie de mettre à jour MBAM avant chaque examen.
Si c'est ok, je te souhaite un bon surf, sois prudente sur le net. En cas de soucis, tu peux revenir sur cette discussion ou cliquer sur mon pseudo, tu auras mon MSN.
Bonne soirée.
++ -
Voilà, je pense que tout est terminé. Dernière question : est-ce que je peux désinstaller tous les logiciels (except CCleaner et MBAM) ?
-
Tu considères ton problème comme résolu ?
-
NoScript est peu compliqué, tu peux le désinstaller, je pense qu'il te gênera plus qu'autre chose. Du moment que tu as WOT et AdBlockPlus, c'est ok ! ;)
-
Je le téléchargeai depuis internet explorer, forcément !
Il est maintenant bien installé. En revanche je ne comprends rien à javascript/noscript ... -
Tu cliques sur "add to firefox" depuis firefox ? Normalement, ce n'est pas un programme, mais un module qui va s'implanter directement dans Firefox.
++
-
J'essaie de télécharger WOT mais il me dit que windows ne peut pas ouvrir ce fichier
-
Si tu le désires, tu peux naviguer avec Firefox. Il est plus sûr que Internet Explorer.
Regarde ici : http://www.mozilla-europe.org/fr/firefox/
Firefox est aujourd'hui très bien développé et sa sécurité, ses fonctions sont des atouts supplémentaires pour un surf agréable...et sécurisé.
Mais attention, tu dois garder IE sur ton pc et le mettre à jour comme si tu t'en servais ! ;) Windows en a besoin pour les mises à jour, installation de certains programmes...etc...
++ -
Je suis rendue aux dernières étapes,je voulais rajouter WOT mais je n'ai pas firefox j'ai internet explorer. Il faudrait que je change ?
-
[ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\UsbFix.txt: trouvé !
C:\UsbFix: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\Doria\Mes documents\Rsit.exe: trouvé !
C:\Documents and Settings\Doria\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\Doria\Bureau\HJTInstall.exe: trouvé !
C:\Documents and Settings\Doria\Bureau\SmitFraudFix.exe: trouvé !
C:\Documents and Settings\Doria\Bureau\UsbFix.exe: trouvé !
C:\Documents and Settings\Doria\Bureau\Rsit.exe: trouvé !
C:\Documents and Settings\Doria\Bureau\SmitFraudfix: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !
C:\Program Files\trend micro\HijackThis: trouvé !
C:\Program Files\trend micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\trend micro\HijackThis\hijackthis.log: trouvé !
---------------------------------
--> Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\Doria\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Doria\Bureau\HJTInstall.exe: supprimé !
C:\Documents and Settings\Doria\Bureau\SmitFraudFix.exe: supprimé !
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\Program Files\trend micro\HijackThis\HijackThis.exe: supprimé !
C:\UsbFix.txt: supprimé !
C:\Documents and Settings\Doria\Mes documents\Rsit.exe: supprimé !
C:\Documents and Settings\Doria\Bureau\UsbFix.exe: supprimé !
C:\Documents and Settings\Doria\Bureau\Rsit.exe: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\Program Files\trend micro\HijackThis\hijackthis.log: supprimé !
C:\UsbFix: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\Doria\Bureau\SmitFraudfix: supprimé !
C:\Program Files\trend micro\HijackThis: supprimé ! -
Si tout est ok de ton côté, du mien aussi ! ;)
Mets ton SP à jour. Windows XP SP3
Relance HijackThis et choisis cette fois "Do a system scan only". La liste créée, coche les lignes suivantes :O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/default.aspx O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Clique sur "Fix Checked".
===========================
Redémarre ton pc. Navigue un peu. Si tout est ok, fais la suite, sinon dis-moi.
==========La suite=============
Nettoyage des outils:
▶ Télécharge ToolsCleaner par A.Rothstein & dj QUIOU sur ton Bureau:
Toolscleaner
▶ Clique sur Recherche et laisse le scan se terminer.
▶ Clique sur Suppression pour finaliser.
▶ Clique sur Quitter, pour que le rapport puisse se créer.
▶ Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
==============================
▶ Télécharge CCleaner, version Slim, sans toolbar:
CCLEANER
▶ Va dans "Options">>"Avancé". Décoche la première ligne.
▶ Va dans la section "Nettoyeur". Lance l'analyse. La liste créée, lance le nettoyage deux fois de suite afin d'obtenir 0bytes supprimé!
▶ Ensuite dans "Registre", lance une recherche des erreurs. La liste créée, fais-les réparer.
▶ Recommence ensuite le cycle Recherche/Réparation des erreurs jusqu'à n'en trouver aucune lors de la recherche.
=================================
Tu peux garder CCleaner et MBAM.
=================================
!! Très Important !!
Supprimer les anciens points de restauration:
▶ Clique droit sur "Poste de travail".
▶ Clique sur "Propriétés".
▶ Clique sur l'onglet "Restauration du système".
▶ Coche la case "Désactiver la restauration...", puis "Appliquer" et valide par "OK".
▶ Redémarre le pc.
▶ Clique droit sur "Poste de travail".
▶ Clique sur "Propriétés".
▶ Clique sur l'onglet "Restauration du système".
▶ Redécoche la case "Désactiver la restauration...", puis "Appliquer" et valide par "OK".
Les points sont supprimés.
Création d'un nouveau point:
▶ Clique sur "démarrer", "tous les programmes", "Accessoires" puis "Outils système".
▶ Clique sur "Restauration du système".
▶ Dans la nouvelle fenêtre, coche la case "Créer un point de restauration".
▶ Clique sur "Suivant".
▶ Entre un nom pour le point de restauration : ce nom doit être assez évocateur (comme: "Après désinfection...")
▶ Clique sur "Créer" et le point de restauration se créé automatiquement.
=============
Pour une navigation plus sûre et plus rapide:
Addon à ajouter à firefox pour le sécuriser:
▶ Ici : WOT : https://addons.mozilla.org/en-US/firefox/addon/wot-safe-browsing-tool/
▶ Explications/Demo ici : http://www.mywot.com/fr/demo
+ ceux-ci: https://www.malekal.com/securiser-le-navigateur-web-firefox-2/
=============
Utile, à lire absolument, quelques minutes de prévention, notamment sur les cracks : https://www.malekal.com/fichiers/projetantimalwares/prevention-protection.pdf
=============
Si tu n'as plus de question et/ou problème, pour moi, c'est ok! (Si tu as encore des questions, n'hésite pas ! )
++ -
J'ai malencontreusement mis les derniers tests en double, dsl. Sinon mon pc à l'air ok
-
############################## | UsbFix V6.037 |
User : Doria (Administrateurs) # ACER-CAB9EEA47C
Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 23:28:03 | 27/09/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) M processor 1.80GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]
C:\ -> Disque fixe local # 44,37 Go (28,15 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 44,86 Go (43,98 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 3,84 Go (3,58 Go free) [UDISK 2.0] # FAT32
G:\ -> Disque fixe local # 298,09 Go (234,73 Go free) [New Volume] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! D:\autorun.inf
Supprimé ! G:\autorun.inf
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{559fb440-66d1-11dc-aaaf-00166f997dc5}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{cf00d972-e970-11dd-ad62-00166f997dc5}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[27/09/2009 19:37|--a------|2324] C:\rapport.txt
[05/08/2004 05:00|-rahs----|4952] C:\Bootfont.bin
[05/08/2004 05:00|-rahs----|251712] C:\ntldr
[05/08/2004 05:00|-rahs----|47564] C:\NTDETECT.COM
[13/08/2007 17:13|-rahs----|216] C:\boot.ini
[06/01/2006 06:31|--a------|0] C:\CONFIG.SYS
[06/01/2006 06:58|--a------|50] C:\AUTOEXEC.BAT
[06/01/2006 06:31|-rahs----|0] C:\IO.SYS
[06/01/2006 06:31|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\hiberfil.sys
[14/05/2006 21:00|-rahs----|79] C:\Preload.aaa
[27/09/2009 23:29|--a------|3461] C:\UsbFix.txt
[19/09/2007 19:50|--a------|168] C:\setupfax.log
[21/01/2008 22:43|--ah-----|244] C:\sqmnoopt00.sqm
[21/01/2008 22:43|--ah-----|268] C:\sqmdata00.sqm
[22/01/2008 13:50|--ah-----|244] C:\sqmnoopt01.sqm
[22/01/2008 13:50|--ah-----|268] C:\sqmdata01.sqm
[29/11/2007 18:54|--ah-----|244] C:\sqmnoopt02.sqm
[29/11/2007 18:54|--ah-----|268] C:\sqmdata02.sqm
[14/12/2007 12:41|--ah-----|244] C:\sqmnoopt03.sqm
[14/12/2007 12:41|--ah-----|268] C:\sqmdata03.sqm
[14/12/2007 21:44|--ah-----|244] C:\sqmnoopt04.sqm
[14/12/2007 21:44|--ah-----|268] C:\sqmdata04.sqm
[15/12/2007 10:54|--ah-----|244] C:\sqmnoopt05.sqm
[15/12/2007 10:54|--ah-----|268] C:\sqmdata05.sqm
[16/12/2007 19:15|--ah-----|244] C:\sqmnoopt06.sqm
[16/12/2007 19:15|--ah-----|268] C:\sqmdata06.sqm
[20/12/2007 07:41|--ah-----|244] C:\sqmnoopt07.sqm
[20/12/2007 07:41|--ah-----|268] C:\sqmdata07.sqm
[10/01/2008 20:55|--ah-----|244] C:\sqmnoopt08.sqm
[10/01/2008 20:55|--ah-----|268] C:\sqmdata08.sqm
[10/01/2008 22:43|--ah-----|244] C:\sqmnoopt09.sqm
[10/01/2008 22:43|--ah-----|268] C:\sqmdata09.sqm
[12/01/2008 17:03|--ah-----|244] C:\sqmnoopt10.sqm
[12/01/2008 17:03|--ah-----|268] C:\sqmdata10.sqm
[13/01/2008 18:47|--ah-----|244] C:\sqmnoopt11.sqm
[13/01/2008 18:47|--ah-----|268] C:\sqmdata11.sqm
[16/01/2008 21:10|--ah-----|244] C:\sqmnoopt12.sqm
[16/01/2008 21:10|--ah-----|268] C:\sqmdata12.sqm
[17/01/2008 18:55|--ah-----|244] C:\sqmnoopt13.sqm
[17/01/2008 18:55|--ah-----|268] C:\sqmdata13.sqm
[18/01/2008 15:41|--ah-----|244] C:\sqmnoopt14.sqm
[18/01/2008 15:41|--ah-----|268] C:\sqmdata14.sqm
[18/01/2008 17:41|--ah-----|244] C:\sqmnoopt15.sqm
[18/01/2008 17:41|--ah-----|268] C:\sqmdata15.sqm
[18/01/2008 20:49|--ah-----|244] C:\sqmnoopt16.sqm
[18/01/2008 20:49|--ah-----|268] C:\sqmdata16.sqm
[19/01/2008 15:59|--ah-----|244] C:\sqmnoopt17.sqm
[19/01/2008 15:59|--ah-----|268] C:\sqmdata17.sqm
[19/01/2008 19:16|--ah-----|244] C:\sqmnoopt18.sqm
[19/01/2008 19:16|--ah-----|268] C:\sqmdata18.sqm
[20/01/2008 12:21|--ah-----|244] C:\sqmnoopt19.sqm
[20/01/2008 12:21|--ah-----|268] C:\sqmdata19.sqm
[?|?|?] C:\pagefile.sys
[12/08/2007 20:39|--ah-----|16384] D:\ffastun.ffo
[12/08/2007 20:39|--ah-----|24576] D:\ffastun.ffl
[12/08/2007 20:39|--ah-----|8192] D:\ffastun0.ffx
[12/08/2007 20:39|--ah-----|4127] D:\ffastun.ffa
[04/08/2004 00:55|--a------|28672] D:\setupSNK.exe
[06/05/2009 17:55|--a------|808] F:\Vert.rtf
[30/09/2008 14:17|--ah-----|4096] F:\._.Trashes
[14/05/2009 11:15|--ah-----|15364] F:\.DS_Store
[26/05/2009 12:36|--a------|896] F:\begreen.rtf
[13/11/2008 17:18|--ah-----|82] F:\._balade.doc
[06/05/2009 17:56|--ah-----|4096] F:\._Vert.rtf
[02/10/2008 17:23|--ah-----|82] F:\._Coccinelles.txt
[02/10/2008 17:23|--ah-----|82] F:\._Show Off kids.txt
[13/11/2008 10:47|--ah-----|413] F:\._Vitrine plus dior ok.doc
[?|?|?] F:\._La Terre vue d'Alban.doc
[02/10/2008 17:23|--ah-----|82] F:\._clas.doc
[05/05/2009 15:15|--a------|964] F:\lebruitdeleau.rtf
[02/10/2008 17:23|--ah-----|82] F:\._Guide doria.xls
[12/11/2008 13:41|--ah-----|82] F:\._Tapis lune.doc
[14/11/2008 15:37|--ah-----|368] F:\._l‚gendes Vio.doc
[06/05/2009 12:07|--ah-----|4096] F:\._lebruitdeleau.rtf
[14/11/2008 14:16|--ah-----|82] F:\._tapis txtedit.txt
[14/11/2008 12:30|--ah-----|419] F:\._l‚gendes So.doc
[06/05/2009 12:16|--a------|2063] F:\fondation cartier.rtf
[06/05/2009 12:17|--ah-----|4096] F:\._fondation cartier.rtf
[26/05/2009 12:36|--ah-----|4096] F:\._begreen.rtf
[14/11/2008 10:17|--ah-----|82] F:\._Tapis lune1.doc
[14/11/2008 10:29|--ah-----|82] F:\._tapis.txt
[06/05/2009 12:25|--a------|46592] F:\l‚gendesviolaine.doc
[11/05/2009 10:29|--ah-----|368] F:\._l‚gendesviolaine.doc
[14/11/2008 12:12|--ah-----|82] F:\._.TemporaryItems
[26/11/2008 15:47|--ah-----|368] F:\._perso.doc
[26/05/2009 11:47|--a------|869] F:\maclarenbaby.rtf
[12/05/2009 17:42|--a------|1025] F:\petitessequences.rtf
[20/11/2008 17:15|--ah-----|368] F:\._perso essai.doc
[12/05/2009 17:42|--ah-----|4096] F:\._petitessequences.rtf
[26/05/2009 11:47|--ah-----|4096] F:\._maclarenbaby.rtf
[11/05/2009 16:25|--a------|834] F:\habitat.rtf
[11/05/2009 15:21|--a------|4146] F:\bb.rtf
[11/05/2009 10:45|--ah-----|4096] F:\._legendesvio.doc
[11/05/2009 15:00|--a------|945] F:\DESIGN.rtf
[11/05/2009 15:00|--ah-----|4096] F:\._DESIGN.rtf
[11/05/2009 10:45|--a------|20480] F:\legendesvio.doc
[11/05/2009 11:42|--a------|569] F:\sommaireguide.rtf
[11/05/2009 11:42|--ah-----|4096] F:\._sommaireguide.rtf
[11/05/2009 15:42|--a------|4176] F:\bb1.rtf
[11/05/2009 15:21|--ah-----|4096] F:\._bb.rtf
[11/05/2009 16:25|--ah-----|4096] F:\._habitat.rtf
[11/05/2009 15:42|--ah-----|4096] F:\._bb1.rtf
[11/05/2009 12:20|--a------|3140] F:\kimiko.rtf
[11/05/2009 12:20|--ah-----|4096] F:\._kimiko.rtf
[11/05/2009 16:11|--ah-----|4096] F:\._cocobohŠme.rtf
[11/05/2009 16:11|--a------|860] F:\cocobohŠme.rtf
[11/05/2009 17:26|--a------|866] F:\petitblancdivoire.rtf
[11/05/2009 17:26|--ah-----|4096] F:\._petitblancdivoire.rtf
[03/10/2005 10:18|--a------|25214] G:\mxoicon2.ico
[01/01/2009 19:47|--ahs----|3072] G:\Thumbs.db
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
# G:\autorun.inf -> Folder created by UsbFix.
############################## | UsbFix V6.037 |
User : Doria (Administrateurs) # ACER-CAB9EEA47C
Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 14:08:57 | 28/09/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) M processor 1.80GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]
C:\ -> Disque fixe local # 44,37 Go (28,21 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 44,86 Go (43,98 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 3,84 Go (3,58 Go free) [UDISK 2.0] # FAT32
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
################## | ! Fin du rapport # UsbFix V6.037 ! | -
Salut ! :)
Comment va ton pc ? Peut-on finaliser ?
++ -
############################## | UsbFix V6.037 |
User : Doria (Administrateurs) # ACER-CAB9EEA47C
Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 23:28:03 | 27/09/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) M processor 1.80GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]
C:\ -> Disque fixe local # 44,37 Go (28,15 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 44,86 Go (43,98 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 3,84 Go (3,58 Go free) [UDISK 2.0] # FAT32
G:\ -> Disque fixe local # 298,09 Go (234,73 Go free) [New Volume] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! D:\autorun.inf
Supprimé ! G:\autorun.inf
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{559fb440-66d1-11dc-aaaf-00166f997dc5}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{cf00d972-e970-11dd-ad62-00166f997dc5}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[27/09/2009 19:37|--a------|2324] C:\rapport.txt
[05/08/2004 05:00|-rahs----|4952] C:\Bootfont.bin
[05/08/2004 05:00|-rahs----|251712] C:\ntldr
[05/08/2004 05:00|-rahs----|47564] C:\NTDETECT.COM
[13/08/2007 17:13|-rahs----|216] C:\boot.ini
[06/01/2006 06:31|--a------|0] C:\CONFIG.SYS
[06/01/2006 06:58|--a------|50] C:\AUTOEXEC.BAT
[06/01/2006 06:31|-rahs----|0] C:\IO.SYS
[06/01/2006 06:31|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\hiberfil.sys
[14/05/2006 21:00|-rahs----|79] C:\Preload.aaa
[27/09/2009 23:29|--a------|3461] C:\UsbFix.txt
[19/09/2007 19:50|--a------|168] C:\setupfax.log
[21/01/2008 22:43|--ah-----|244] C:\sqmnoopt00.sqm
[21/01/2008 22:43|--ah-----|268] C:\sqmdata00.sqm
[22/01/2008 13:50|--ah-----|244] C:\sqmnoopt01.sqm
[22/01/2008 13:50|--ah-----|268] C:\sqmdata01.sqm
[29/11/2007 18:54|--ah-----|244] C:\sqmnoopt02.sqm
[29/11/2007 18:54|--ah-----|268] C:\sqmdata02.sqm
[14/12/2007 12:41|--ah-----|244] C:\sqmnoopt03.sqm
[14/12/2007 12:41|--ah-----|268] C:\sqmdata03.sqm
[14/12/2007 21:44|--ah-----|244] C:\sqmnoopt04.sqm
[14/12/2007 21:44|--ah-----|268] C:\sqmdata04.sqm
[15/12/2007 10:54|--ah-----|244] C:\sqmnoopt05.sqm
[15/12/2007 10:54|--ah-----|268] C:\sqmdata05.sqm
[16/12/2007 19:15|--ah-----|244] C:\sqmnoopt06.sqm
[16/12/2007 19:15|--ah-----|268] C:\sqmdata06.sqm
[20/12/2007 07:41|--ah-----|244] C:\sqmnoopt07.sqm
[20/12/2007 07:41|--ah-----|268] C:\sqmdata07.sqm
[10/01/2008 20:55|--ah-----|244] C:\sqmnoopt08.sqm
[10/01/2008 20:55|--ah-----|268] C:\sqmdata08.sqm
[10/01/2008 22:43|--ah-----|244] C:\sqmnoopt09.sqm
[10/01/2008 22:43|--ah-----|268] C:\sqmdata09.sqm
[12/01/2008 17:03|--ah-----|244] C:\sqmnoopt10.sqm
[12/01/2008 17:03|--ah-----|268] C:\sqmdata10.sqm
[13/01/2008 18:47|--ah-----|244] C:\sqmnoopt11.sqm
[13/01/2008 18:47|--ah-----|268] C:\sqmdata11.sqm
[16/01/2008 21:10|--ah-----|244] C:\sqmnoopt12.sqm
[16/01/2008 21:10|--ah-----|268] C:\sqmdata12.sqm
[17/01/2008 18:55|--ah-----|244] C:\sqmnoopt13.sqm
[17/01/2008 18:55|--ah-----|268] C:\sqmdata13.sqm
[18/01/2008 15:41|--ah-----|244] C:\sqmnoopt14.sqm
[18/01/2008 15:41|--ah-----|268] C:\sqmdata14.sqm
[18/01/2008 17:41|--ah-----|244] C:\sqmnoopt15.sqm
[18/01/2008 17:41|--ah-----|268] C:\sqmdata15.sqm
[18/01/2008 20:49|--ah-----|244] C:\sqmnoopt16.sqm
[18/01/2008 20:49|--ah-----|268] C:\sqmdata16.sqm
[19/01/2008 15:59|--ah-----|244] C:\sqmnoopt17.sqm
[19/01/2008 15:59|--ah-----|268] C:\sqmdata17.sqm
[19/01/2008 19:16|--ah-----|244] C:\sqmnoopt18.sqm
[19/01/2008 19:16|--ah-----|268] C:\sqmdata18.sqm
[20/01/2008 12:21|--ah-----|244] C:\sqmnoopt19.sqm
[20/01/2008 12:21|--ah-----|268] C:\sqmdata19.sqm
[?|?|?] C:\pagefile.sys
[12/08/2007 20:39|--ah-----|16384] D:\ffastun.ffo
[12/08/2007 20:39|--ah-----|24576] D:\ffastun.ffl
[12/08/2007 20:39|--ah-----|8192] D:\ffastun0.ffx
[12/08/2007 20:39|--ah-----|4127] D:\ffastun.ffa
[04/08/2004 00:55|--a------|28672] D:\setupSNK.exe
[06/05/2009 17:55|--a------|808] F:\Vert.rtf
[30/09/2008 14:17|--ah-----|4096] F:\._.Trashes
[14/05/2009 11:15|--ah-----|15364] F:\.DS_Store
[26/05/2009 12:36|--a------|896] F:\begreen.rtf
[13/11/2008 17:18|--ah-----|82] F:\._balade.doc
[06/05/2009 17:56|--ah-----|4096] F:\._Vert.rtf
[02/10/2008 17:23|--ah-----|82] F:\._Coccinelles.txt
[02/10/2008 17:23|--ah-----|82] F:\._Show Off kids.txt
[13/11/2008 10:47|--ah-----|413] F:\._Vitrine plus dior ok.doc
[?|?|?] F:\._La Terre vue d'Alban.doc
[02/10/2008 17:23|--ah-----|82] F:\._clas.doc
[05/05/2009 15:15|--a------|964] F:\lebruitdeleau.rtf
[02/10/2008 17:23|--ah-----|82] F:\._Guide doria.xls
[12/11/2008 13:41|--ah-----|82] F:\._Tapis lune.doc
[14/11/2008 15:37|--ah-----|368] F:\._l‚gendes Vio.doc
[06/05/2009 12:07|--ah-----|4096] F:\._lebruitdeleau.rtf
[14/11/2008 14:16|--ah-----|82] F:\._tapis txtedit.txt
[14/11/2008 12:30|--ah-----|419] F:\._l‚gendes So.doc
[06/05/2009 12:16|--a------|2063] F:\fondation cartier.rtf
[06/05/2009 12:17|--ah-----|4096] F:\._fondation cartier.rtf
[26/05/2009 12:36|--ah-----|4096] F:\._begreen.rtf
[14/11/2008 10:17|--ah-----|82] F:\._Tapis lune1.doc
[14/11/2008 10:29|--ah-----|82] F:\._tapis.txt
[06/05/2009 12:25|--a------|46592] F:\l‚gendesviolaine.doc
[11/05/2009 10:29|--ah-----|368] F:\._l‚gendesviolaine.doc
[14/11/2008 12:12|--ah-----|82] F:\._.TemporaryItems
[26/11/2008 15:47|--ah-----|368] F:\._perso.doc
[26/05/2009 11:47|--a------|869] F:\maclarenbaby.rtf
[12/05/2009 17:42|--a------|1025] F:\petitessequences.rtf
[20/11/2008 17:15|--ah-----|368] F:\._perso essai.doc
[12/05/2009 17:42|--ah-----|4096] F:\._petitessequences.rtf
[26/05/2009 11:47|--ah-----|4096] F:\._maclarenbaby.rtf
[11/05/2009 16:25|--a------|834] F:\habitat.rtf
[11/05/2009 15:21|--a------|4146] F:\bb.rtf
[11/05/2009 10:45|--ah-----|4096] F:\._legendesvio.doc
[11/05/2009 15:00|--a------|945] F:\DESIGN.rtf
[11/05/2009 15:00|--ah-----|4096] F:\._DESIGN.rtf
[11/05/2009 10:45|--a------|20480] F:\legendesvio.doc
[11/05/2009 11:42|--a------|569] F:\sommaireguide.rtf
[11/05/2009 11:42|--ah-----|4096] F:\._sommaireguide.rtf
[11/05/2009 15:42|--a------|4176] F:\bb1.rtf
[11/05/2009 15:21|--ah-----|4096] F:\._bb.rtf
[11/05/2009 16:25|--ah-----|4096] F:\._habitat.rtf
[11/05/2009 15:42|--ah-----|4096] F:\._bb1.rtf
[11/05/2009 12:20|--a------|3140] F:\kimiko.rtf
[11/05/2009 12:20|--ah-----|4096] F:\._kimiko.rtf
[11/05/2009 16:11|--ah-----|4096] F:\._cocobohŠme.rtf
[11/05/2009 16:11|--a------|860] F:\cocobohŠme.rtf
[11/05/2009 17:26|--a------|866] F:\petitblancdivoire.rtf
[11/05/2009 17:26|--ah-----|4096] F:\._petitblancdivoire.rtf
[03/10/2005 10:18|--a------|25214] G:\mxoicon2.ico
[01/01/2009 19:47|--ahs----|3072] G:\Thumbs.db
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
# G:\autorun.inf -> Folder created by UsbFix.
################## | Upload |
Veuillez envoyer le fichier : C:\DOCUME~1\Doria\Bureau\UsbFix_Upload_Me_ACER-CAB9EEA47C.zip : https://www.androidworld.fr/
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.037 ! |
############################## | UsbFix V6.037 |
User : Doria (Administrateurs) # ACER-CAB9EEA47C
Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 23:36:28 | 27/09/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) M processor 1.80GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]
C:\ -> Disque fixe local # 44,37 Go (28,16 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 44,86 Go (43,98 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 3,84 Go (3,58 Go free) [UDISK 2.0] # FAT32
G:\ -> Disque fixe local # 298,09 Go (234,73 Go free) [New Volume] # NTFS
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
# G:\autorun.inf -> Folder created by UsbFix.
################## | ! Fin du rapport # UsbFix V6.037 ! | -
Je fais les derniers tests, encore merci et à demain alors.
-
Ok, dernier post avant que je te laisse pour ce soir :
UsbFix XP
Option 2 : suppression
Tutoriel nettoyage
▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés sans les ouvrir
▶ Double clique sur le raccourci UsbFix présent sur ton bureau
▶ Choisis l'option 2 ( Suppression )
▶ Ton bureau disparaîtra et le pc redémarrera .
▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra avec le bureau .
* Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
/!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/
▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.
▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.
▶ Merci d'avance pour ta contribution !!
=====================================
UsbFix XP
Option 3 : vaccination
▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir
▶ Double clique sur le raccourci UsbFix présent sur ton bureau .
▶ Choisis l'option 3 ( Vaccination )
▶ Laisse travailler l'outil.
▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra.
* Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )
++
A demain pour la fin des aventures ! :) Tu pourras me dire comment va ton pc ?
+
-
Merci pour l'info.
Voici la dernière analyse
############################## | UsbFix V6.037 |
User : Doria (Administrateurs) # ACER-CAB9EEA47C
Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 23:10:34 | 27/09/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) M processor 1.80GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]
C:\ -> Disque fixe local # 44,37 Go (28,19 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 44,86 Go (43,98 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 3,84 Go (3,58 Go free) [UDISK 2.0] # FAT32
G:\ -> Disque fixe local # 298,09 Go (234,73 Go free) [New Volume] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\acer\Empowering Technology\ePower\epm-dm.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Documents and Settings\Doria\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\DOCUME~1\Doria\LOCALS~1\Temp\jre-6u15-windows-i586-iftw.exe
################## | Fichiers # Dossiers infectieux |
D:\autorun.inf
G:\autorun.inf
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{559fb440-66d1-11dc-aaaf-00166f997dc5}
Shell\Auto\command =AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
HKCU\..\..\Explorer\MountPoints2\{cf00d972-e970-11dd-ad62-00166f997dc5}
Shell\AutoRun\command =F:\WDSetup.exe
################## | ! Fin du rapport # UsbFix V6.037 ! | -
Re.
AVG est très bien ! Même en gratuit. Je ne te conseille pas d'antivirus payant ! ;)
C'est juste que tu as Norton qui tourne aussi sur ton pc :
Suis cette procédure pour supprimer toute trace de Norton:
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924
========================
Tu as encore des mises à jour à faire, puis la finalisation, on verra ça demain, si tu veux, je vais quitter le forum pour ce soir ! :)
========================
Avant de partir ce soir, tu as également une infection qui se transmet par Disques Amovibles. On va donc la traiter :
UsbFix XP
Option 1 : recherche
▶ Télécharge UsbFix de C_XX & Chiquitine29
▶ Tutoriel d'installation
▶ Tutoriel recherche
▶ Lance l'installation avec les paramètres par défaut
▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir
▶ Double clique sur le raccourci UsbFix sur ton bureau
▶ Choisis l'option 1 (recherche)
▶ Laisse travailler l'outil
▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra
* Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
* Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus
++
- 1
- 2