Trojan win32.small-lx
Résoluvoila en defragmentant mon disque, je lis le rapport qui me signale que certains fichiers ne peuvent etre defragmentés.
parmi eux je remarque (par sa taille : 1,4 Go) un fichier 493.tmp sous c:\
je fais une analyse avast qui m'informe qu'il est infecté par le virus Win32:Small-LX [Trj]
Impossible de le supprimer ou mettre en quarantaine.
J'ai forcé le déplacement et le fichier est actuellement sous C:\Program Files\Alwil Software\Avast4\DATA\moved.
voila mon log hijack.
Merci de votre aide.
Logfile of HijackThis v1.99.1
Scan saved at 15:15:12, on 24/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LOUBEAU\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\system32\msmsgs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Configuration: Avast A2 free Spybot Ccleaner Fixwareout Windows XP Internet Explorer 7.0
26 réponses
Le fil aborde un problème de défragmentation révélant un fichier 493.tmp sur C:\ qui, après analyse Avast, est identifié comme Win32:Small-LX [Trj] et déplacé dans le répertoire moved. Le message comprend un log HijackThis détaillé et montre de nombreuses entrées de démarrage, des barres d'outils et des composants susceptibles d'être associés à des logiciels malveillants. Parmi les solutions proposées, l'outil SDFix est préconisé pour supprimer les trojans et nettoyer le registre, avec redémarrage en mode sans échec et rapport à coller dans la discussion. En cas de perceptions contradictoires, certains échanges mentionnent des scans antivirus négatifs et des vérifications complémentaires, avant qu'une étape finale de nettoyage ne confirme potentiellement la levée de l'infection.
-
Contributeur sécuritéSalut
Cool :)
Non lol , juste par rapport aux rapports que tu m as donné :)
Bonne continuation -
ecoute je pense que c bon.
je n'ai plus rien ds moved.
tout parait ok.
c cool
merci bcp.
comment tu savais que c'etait ces fichiers ?
tu peux acceder a mon pc ?
merci encore !
a + (j'espere pas ! mdr) -
Contributeur sécuritéSalut
Moved correspond a la quarantaine de Avast :)
Dis moi ce que je peux pour toi ?!
A+ -
salut,
en fait je peux pas dire que j'ai de gros soucis.
parfois, lorsque je n'ai plus accès à internet sans fil, ça me marque "aucun dispositif" qd j'appuie sur le bouton (au lieu de wireless lan activé ou désactivé).
Hier, ça me l'a fait après avoir lancé fixwareout.
Alors, j'éteins mon pc, si je redémarre tout de suite, en général, je ne peux tjs pas me connecter. mais qq heures apres, c bon.
Alors, j'ai tjs ce fichier infecté par trojan win32 small lx dans le repertoire moved d'avast...
C space, je viens de m'apercevoir qu'il n'y ait plus alors qu'hier il y était encore (c pê fixwareout).
Il faut que je défragmente mon pc. -
Contributeur sécuritéSalut
redemarre et dis moi ou en sont tes soucis?
A+ -
re,
c fait
et maintenant ?
que faut il faire ?
mon pc est clean ?
a+ -
Contributeur sécuritéOk pas grave.
Supprime:
C:\WINDOWS\x74ca5e40.tmp
A+ -
ça me marque à chq fois ça sur le 1er lien :
Cette erreur (HTTP 500 Erreur interne au serveur) signifie que le site Web que vous visitez a rencontré un problème de serveur qui a empêché l’affichage de la page Web. -
690 KO
-
Contributeur sécuritéSalut
prkoi le 1er n'a pas marché?
Il pese combien?
A+ -
sans oublier le fichier de 1,4 Go que j'ai déplacé dans le répertoire moved d'avast (cf mon premier message)
-
salut
ça n'a pas marché le premier lien.. -
Contributeur sécuritéSalut
Tu as une nouvelle infection intéressante sur ton ordinateur.
Contrôle des données :
Peux-tu afficher tous les fichiers sur ton ordinateur ? Vérifie ton paramétrage :
dans Windows Explorer :
>Outils > Options des dossiers > onglet "Affichage" > Fichiers et dossiers cachés > activer "Afficher les fichiers et dossiers cachés" > décocher Masquer les extensions des fichiers dont le type est connu > décocher "Masquer les fichiers du système d'exploitation (recommandé) > Appliquer > Appliquer à tous les dossiers et confirmer par OK > OK pour quitter
S'il te plaît, télécharge ces fichiers
C:\WINDOWS\x74ca5e40.tmp
1. -> S!Ri -remontée des fichiers (*). http://siri.urz.free.fr/upload/
et ensuite:
Sur cette page:
http://secubox.gateweb.org/mad.php
Merci, et confirme moi que les 2 upload ont fonctionné.
A+ -
je mets le rapport du dernier scan spybot que je viens de faire.
J'ai réglé en priorité du scan absolue. Il me met "aucun mouchard détecte". mais il met ensuite pas mal de truc en vert mais je sais pas si je dois les cocher et les supprimer...
--- Search result list ---
Common Dialogs: History (12 files) (Clé du registre, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
MS Office 9.0: Recently used files (116 files) (Répertoire, nothing done)
C:\Documents and Settings\LOUBEAU\Application Data\Microsoft\Office\Récents\
Log: Activity: SchedLgU.Txt (Sauver le fichier, nothing done)
C:\WINDOWS\SchedLgU.Txt
Log: Shutdown: System32\wbem\logs\wbemess.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.log
Log: Shutdown: System32\wbem\logs\wmiprov.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiprov.log
Adobe Acrobat Reader 6: Recent file #1 (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles\c1
Alcohol 120%: Last search path (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Alcohol Soft\Alcohol 120%\Basic\Image Finder\Current Dir!=
Alcohol 120%: Images history (8 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Alcohol Soft\Alcohol 120%\Images
Alcohol 120%: Image location history (7 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Alcohol Soft\Alcohol 120%\Images\Location
Ahead Nero Burning Rom: Last encoding directory (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\EncodingLastDir!=
Ahead Nero Burning Rom: Compilation directory (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\NeroCompilation!=
Ahead Nero Burning Rom: Save tracks directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero - Burning Rom\SaveTrackOptions\Stdflist!=B=
Ahead Nero Burning Rom: Last encoding directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero - Burning Rom\Settings\EncodingLastDir!=
Ahead Nero Burning Rom: Compilation directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero - Burning Rom\Settings\NeroCompilation!=
Ahead Nero Wave Editor: Last open file type (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero Wave Editor\General\LastOpenFilter
Internet Explorer: Typed URL list (1 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Internet Explorer\TypedURLs
Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
MS Media Player: Search terms history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\AutoComplete\MediaSearch
MS Media Player: Last selected node (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\MediaLibraryUI\MLLastSelectedNode!=
MS Media Player: Client ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Anonymous ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0
MS Direct3D: Most recent application (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name!=
MS DirectDraw: Most recent application (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name!=
MS DirectInput: Most recent application (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\DirectInput\MostRecentApplication\Name!=
MS DirectInput: Most recent application ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\DirectInput\MostRecentApplication\Id!=
MS Office 9.0: Internet history (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Common\Internet\LocationOfComponents
MS Office 9.0: Internet history (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Common\Internet\UseRWHlinkNavigation
MS Office 9.0: Access recent file (5 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Access\Settings
MS Office 9.0 (Word): Recently used file list (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Word\Data\Settings
MS Office 9.0 (Excel): Recent files (4 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Excel\Recent Files
MS Office 9.0 (PowerPoint): Recent file list (9 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\PowerPoint\Recent File List
MS Search Assistant: Typed search terms history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Search Assistant\ACMru
Windows: Drivers installation paths (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources!=
Windows.OpenWith: Open with list - .ACE extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ACE\OpenWithList
Windows.OpenWith: Open with list - .ASF extension (3 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ASF\OpenWithList
Windows.OpenWith: Open with list - .ASX extension (3 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ASX\OpenWithList
Windows.OpenWith: Open with list - .AVI extension (6 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList
Windows.OpenWith: Open with list - .BAK extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BAK\OpenWithList
Windows.OpenWith: Open with list - .BIN extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList
Windows.OpenWith: Open with list - .BMP extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList
Windows.OpenWith: Open with list - .CAB extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CAB\OpenWithList
Windows.OpenWith: Open with list - .CDA extension (4 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\OpenWithList
Windows.OpenWith: Open with list - .CDM extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDM\OpenWithList
Windows.OpenWith: Open with list - .CHM extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CHM\OpenWithList
Windows.OpenWith: Open with list - .CUE extension (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CUE\OpenWithList
Windows Explorer: Recent wallpaper list (501 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
Windows Explorer: Stream history (151 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: User Assistant history IE (142 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Explorer: User Assistant history files (282 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: Last visited history (2 fichiers) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Windows Explorer: Recent file global history (Clé du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: Recent file global history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: Recent file global history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: Recent file global history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: Recent file global history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: Last Copy/MoveTo folder (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CopyMoveTo\LastFolder
Windows Media SDK: Computer name (Modification du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Computer name (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Computer name (Modification du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Unique ID (Modification du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Unique ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Unique ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Cookie: Cookie (29) (Cookie, nothing done)
Cache: Cache (538) (Cache, nothing done)
Félicitations!: Aucun mouchard n'a été trouvé. () -
donc :
C:\WINDOWS\x74ca5e40.tmp
est infecté :
BitDefender Found Adware.Psguard.A, Adware.Winhound.B
NOD32 Found Win32/Adware.PSGuard application -
Contributeur sécuritéS'il trouve nothing a tous, pas la peine de me montrer mais fais bien un scan des 3 autres aussi:
C:\WINDOWS\MOTA113.exe
C:\WINDOWS\system32\x.264.exe
C:\WINDOWS\x74ca5e40.tmp -
je ne te mets pas ce qu'il y a ds le tableau statistics ?
sinon, l'analyse a foundé nothing pour meta4.exe (dans scanner results)
merci encore regis59 ! -
Contributeur sécuritéIl est ok, tu peux faire les autres?
A+ -
hello
je te colle ceci (fait pour x2.64.exe) ?
Scanner results
Scan taken on 26 Mar 2007 17:38:11 (GMT)
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing -
Contributeur sécuritéSalut,
Voici la liste:
C:\WINDOWS\x2.64.exe
C:\WINDOWS\meta4.exe
C:\WINDOWS\MOTA113.exe
C:\WINDOWS\system32\x.264.exe
C:\WINDOWS\x74ca5e40.tmp
Vas sur le site https://virusscan.jotti.org/
- Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne un fichier de la liste.
- Clic sur submit toujours en haut à droite
- Le scan va se lancer, ça va prendre un petit instant
- En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.
Aide : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId662799
Puis fais l'analyse pour chaque fichier.
- 1
- 2