Trojans et effets...

Bonjour,
Je ne voudrais pas me faire trop remarquer, mais je voudrais juste sauver le cadeau d'anniv de ma chérie ( son pc ) que faire donc des trojans bloqués par avast, que faire des fichiers infectés, comment savoir si il a été endommagé.J'ai besoin de vos connaissances je suis dans les choux avec tous ce vocabulaire. MERCI !!!!
Configuration: Windows Vista
Firefox 2.0.0.8

76 réponses

Résumé de la discussion

Des trojans bloqués par Avast soulèvent des questions sur l’intégrité des fichiers infectés et l’éventuel dommage sur le PC sous Windows Vista, ainsi que sur les mesures à prendre pour sécuriser le système. Plusieurs conseils recommandent des analyses croisées avec VirusTotal et Jotti's, l’utilisation de HijackThis pour générer un rapport, notamment pour identifier les éléments suspects et vérifier des fichiers cachés. En dernier lieu, l’échange souligne l’importance des sauvegardes et d’évaluer les résultats sur plusieurs outils pour éviter les fausses alertes ou les suppressions inutiles, sans conclure à une résolution immédiate.

Bobot (l’IA à votre service)
  1. Contributeur
    salut luxav,

    oui mais le en resolut...

    bonne continuation.

    BYE`
    1. Salut G!rly,

      Donc le probleme est réglé si je comprends ? dois je mettre ce topic en probleme résolu ? Merci pour tout ......
      1. Contributeur
        salut,

        a dire vrai je ne vois pas de mauvais processus dans le rapport de icesword...

        je ne connais pas d´autre par feu compatible vista...

        et pour ton probleme avec la wifi, tu pourrais poster un nouveau message sur le forum internet de ce meme site...

        tu voie je suis assez limité en presence de vista, un peu comme tout le monde...

        voila.
        1. Salut G!rly,

          Ben en fait, non !! ca ne plante plus ...
          ca veut donc dire que tout est résolu ? si oui, que me conseilles tu pour protéger le pc des éventuels futurs malware ? Zone alarm bien que compatible avec Vista ( le lien que tu m'as conseillé ) n'a pas pu etre installé, car l'assistant de compatibilité des programmes m'indique une ou plusieurs incompatibilité avec TrueVector Device Driver.. J'ai donc laché l'affaire, tu as peut etre autre chose à me proposer pour le remplacer.
          Ha oui une dernière chose à l'allumage un message apparé sur le bureau et me dis que le point d'entrée( je n'ai pas noté son nom mais je sais que ca a un rapport avec le routeur wifi ) est introuvable dans bibliotheque active. J'ai essayé de tout désinstaller puor le réinstaller mais impossible !!!
          1. Contributeur
            bonjour luxav,

            d´apres les analyses de virus total et jottti´s il n´y a pas lieu de s´inquiété sur ce processus, ce que tu as vu sur le lien que je t´ai montré
            parle bien du meme fichier mais situé a un endroit different...

            toujours des problemes de plantage?
            1. Salut G!rly !

              P....n !!!! bonjour le réveil!!!! Donc c'est une énorme saloperie !
              C'est bien ce qui suit que je devais lire ? ca n'a rien de rassurant dis moi.:

              This is an undesirable program.

              This file has been identified as a program that is undesirable to have running on your computer. This consists of programs that are misleading, harmful, or undesirable.

              If the description states that it is a piece of malware, you should immediately run an antivirus and antispyware program. If that does not help, feel free to ask us for assistance in the forums.
              Click here to Run a scan for related errors

              Name: MSIEXEC
              Filename: MSIEXEC.EXE
              Fix MSIEXEC.EXE errors: Try a Registry Scan
              Command: Unknown at this time.
              Description: Added by VBS/Yosenio-A. The VIRUS will overwrite files on the infected computer, adding .vbs to the file extension.
              File Location: %Windir%
              Startup Type: This startup entry is started automatically from a Run, RunOnce, RunServices, or RunServicesOnce entry in the registry.
              HijackThis Category: O4 Entry
              Note: %Windir% refers to the Windows installation folder. By default, this is C:\Windows for Windows 95/98/ME/XP or C:\Winnt for Windows NT/2000.
              Removal Instructions: How to remove a Trojan, Virus, Worm, or other Malware

              Bon alors voici le jotti :

              Datei: msiexec.exe
              Auslastung:
              0% 100%
              Status:
              OK (Anmerkung: diese Datei wurde bereits vorher gescannt. Die Scanergebnisse werden daher nicht in der Datenbank gespeichert.)
              Entdeckte Packprogramme:
              -
              Bit9 rapportiert: No threat detected (more info)

              A-Squared
              Keine Viren gefunden
              AntiVir
              Keine Viren gefunden
              ArcaVir
              Keine Viren gefunden
              Avast
              Keine Viren gefunden
              AVG Antivirus
              Keine Viren gefunden
              BitDefender
              Keine Viren gefunden
              ClamAV
              Keine Viren gefunden
              CPsecure
              Keine Viren gefunden
              Dr.Web
              Keine Viren gefunden
              F-Prot Antivirus
              Keine Viren gefunden
              F-Secure Anti-Virus
              Keine Viren gefunden
              Fortinet
              Keine Viren gefunden
              Kaspersky Anti-Virus
              Keine Viren gefunden
              NOD32
              Keine Viren gefunden
              Norman Virus Control
              Keine Viren gefunden
              Panda Antivirus
              Keine Viren gefunden
              Rising Antivirus
              Keine Viren gefunden
              Sophos Antivirus
              Keine Viren gefunden
              VirusBuster
              Keine Viren gefunden
              VBA32
              Keine Viren gefunden
              1. Bonsoir G!rly,

                Voici le scan du fichier msiexec.exe !!..

                Fichier msiexec.exe reçu le 2007.11.04 19:33:42 (CET)
                Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
                Résultat: 0/32 (0%)
                en train de charger les informations du serveur...
                Votre fichier est dans la file d'attente, en position: 5.
                L'heure estimée de démarrage est entre 56 et 81 secondes.
                Ne fermez pas la fenêtre avant la fin de l'analyse.
                L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                les résultats seront affichés au fur et à mesure de leur génération.
                Formaté Formaté
                Impression des résultats Impression des résultats
                Votre fichier a expiré ou n'existe pas.
                Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

                Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
                Email:

                Antivirus Version Dernière mise à jour Résultat
                AhnLab-V3 2007.11.3.0 2007.11.02 -
                AntiVir 7.6.0.30 2007.11.04 -
                Authentium 4.93.8 2007.11.03 -
                Avast 4.7.1074.0 2007.11.04 -
                AVG 7.5.0.503 2007.11.04 -
                BitDefender 7.2 2007.11.04 -
                CAT-QuickHeal 9.00 2007.11.03 -
                ClamAV 0.91.2 2007.11.04 -
                DrWeb 4.44.0.09170 2007.11.04 -
                eSafe 7.0.15.0 2007.10.28 -
                eTrust-Vet 31.2.5264 2007.11.02 -
                Ewido 4.0 2007.11.04 -
                FileAdvisor 1 2007.11.04 -
                Fortinet 3.11.0.0 2007.10.19 -
                F-Prot 4.4.2.54 2007.11.03 -
                F-Secure 6.70.13030.0 2007.11.04 -
                Ikarus T3.1.1.12 2007.11.04 -
                Kaspersky 7.0.0.125 2007.11.04 -
                McAfee 5155 2007.11.02 -
                Microsoft 1.2908 2007.11.04 -
                NOD32v2 2636 2007.11.03 -
                Norman 5.80.02 2007.11.02 -
                Panda 9.0.0.4 2007.11.04 -
                Prevx1 V2 2007.11.04 -
                Rising 20.16.62.00 2007.11.04 -
                Sophos 4.23.0 2007.11.04 -
                Sunbelt 2.2.907.0 2007.11.02 -
                Symantec 10 2007.11.04 -
                TheHacker 6.2.9.110 2007.10.27 -
                VBA32 3.12.2.4 2007.11.03 -
                VirusBuster 4.3.26:9 2007.11.03 -
                Webwasher-Gateway 6.6.1 2007.11.04 -
                Information additionnelle
                File size: 71680 bytes
                MD5: b038d40785fa669bd8c3e0252909b4c2
                SHA1: cc33f56cc34d1a0c996d527f10ee66bb73785ddb

                à +
                1. Bonjour G!rly,

                  Pour l'instant ce site est inaccessible !!. :-)

                  à +
                  1. Contributeur
                    bonsoir luxav,

                    j´aimerais que tu fasse analyser ce fichier :

                    C:\Windows\System32\msiexec.exe

                    http://virusscan.jotti.org/de/

                    post le rapport...

                    affiche les fichiers cachés pour le trouver si necessaire.

                    @+
                    1. Bonjour G!rly,
                      voici le rapport icesword.

                      Merci.....

                      Process:

                      System Idle Process
                      System
                      C:\Windows\System32\drivers\XAudio.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      C:\Windows\System32\smss.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\csrss.exe
                      C:\Windows\System32\wininit.exe
                      C:\Program Files\Spyware Doctor\svcntaux.exe
                      C:\Windows\System32\services.exe
                      C:\Windows\System32\lsass.exe
                      C:\Windows\System32\lsm.exe
                      C:\Windows\System32\svchost.exe
                      C:\Program Files\Spyware Doctor\swdsvc.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\audiodg.exe
                      C:\Windows\System32\SLsvc.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Users\pccity\Desktop\is120en_vista\IceSword.exe
                      C:\Program Files\a-squared Free\a2service.exe
                      C:\Windows\System32\taskeng.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Windows\System32\wbem\WmiPrvSE.exe
                      C:\Windows\System32\winlogon.exe
                      C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
                      C:\Windows\System32\SearchIndexer.exe
                      C:\Windows\System32\taskeng.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\Windows\System32\igfxtray.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\MSN Messenger\msnmsgr.exe
                      C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Spyware Doctor\SDTrayApp.exe
                      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                      C:\Program Files\HP\QuickPlay\QPService.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Windows\System32\msiexec.exe
                      C:\Windows\System32\csrss.exe
                      C:\Windows\explorer.exe
                      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                      C:\Windows\System32\dwm.exe
                      1. Contributeur
                        bonjour,

                        Télécharge IceSword ici:
                        http://202.38.64.10/~jfpan/download/is120en_vista.zip
                        Enregistre le sur ton bureau.

                        Fais un clic droit sur le dossier is120en_vista.zip que tu viens de télécharger et clic sur "Extraire tout".
                        Dans le nouveau dossier nommé is120en_vista qui sera apparu sur ton bureau, double clic sur le fichier IceSword.exe.

                        A gauche dans la fenêtre du programme, clic sur "Process" (icône en forme de roue crantée).
                        Une fois fait, click dans le menu du haut sur "LOG" (en bleu).

                        Une boîte de dialogue va s'ouvrir, donne un nom au fichier rapport et enregistre le à un endroit ou tu seras sure de le retrouver facilement (le bureau...).
                        Ensuite referme la fenêtre d'icesword et n'y touche plus :-).

                        Si tu as suivie mon exemple tu auras donc sur ton bureau un fichier .log
                        Ouvre-le et copie et colle tout son contenu dans ton prochain message.
                        1. Bonjour G!rly,

                          Voici le rapport antivir!
                          Au fait , as tu une idée sur le fait qu'il plante ( il semble "réfléchir" (sablier apparent ) comme si il était trés trés trés lent, et ne répond plus aux commandes !!!!......
                          Merci @+

                          AntiVir PersonalEdition Classic
                          Report file date: vendredi 2 novembre 2007 01:30

                          Scanning for 912530 virus strains and unwanted programs.

                          Licensed to: Avira AntiVir PersonalEdition Classic
                          Serial number: 0000149996-ADJIE-0001
                          Platform: Windows Vista
                          Windows version: (plain) [6.0.6000]
                          Username: SYSTEM
                          Computer name: PC-DE-LUCIE

                          Version information:
                          BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                          AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                          AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                          LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                          LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 00:08:19
                          ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 00:08:20
                          ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 26/10/2007 00:08:20
                          ANTIVIR3.VDF : 7.0.0.162 117760 Bytes 01/11/2007 00:08:20
                          AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 02/11/2007 00:08:24
                          AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                          AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                          AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                          AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
                          AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                          AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                          AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                          NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                          RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                          RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                          SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                          Configuration settings for the scan:
                          Jobname..........................: Complete system scan
                          Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                          Logging..........................: low
                          Primary action...................: interactive
                          Secondary action.................: ignore
                          Scan master boot sector..........: off
                          Scan boot sector.................: on
                          Boot sectors.....................: D:,
                          Scan memory......................: on
                          Process scan.....................: on
                          Scan registry....................: on
                          Search for rootkits..............: off
                          Scan all files...................: Intelligent file selection
                          Scan archives....................: on
                          Recursion depth..................: 20
                          Smart extensions.................: on
                          Macro heuristic..................: on
                          File heuristic...................: medium

                          Start of the scan: vendredi 2 novembre 2007 01:30

                          The scan of running processes will be started
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                          Scan process 'sched.exe' - '1' Module(s) have been scanned
                          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                          Scan process 'avguard.exe' - '1' Module(s) have been scanned
                          Scan process 'avgas.exe' - '1' Module(s) have been scanned
                          Scan process 'guard.exe' - '0' Module(s) have been scanned
                          Scan process 'firefox.exe' - '1' Module(s) have been scanned
                          Scan process 'conime.exe' - '1' Module(s) have been scanned
                          Scan process 'HPQTOA~1.EXE' - '1' Module(s) have been scanned
                          Scan process 'HPHC_Service.exe' - '1' Module(s) have been scanned
                          Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                          Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                          Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                          Scan process 'SDTrayApp.exe' - '1' Module(s) have been scanned
                          Scan process 'jusched.exe' - '1' Module(s) have been scanned
                          Scan process 'HPWAMain.exe' - '1' Module(s) have been scanned
                          Scan process 'WiFiMsg.exe' - '1' Module(s) have been scanned
                          Scan process 'QLBCTRL.exe' - '1' Module(s) have been scanned
                          Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                          Scan process 'QPService.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
                          Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
                          Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
                          Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                          Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                          Scan process 'explorer.exe' - '1' Module(s) have been scanned
                          Scan process 'dwm.exe' - '1' Module(s) have been scanned
                          Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                          Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                          Scan process 'hpqwmiex.exe' - '1' Module(s) have been scanned
                          Scan process 'XAudio.exe' - '1' Module(s) have been scanned
                          Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'swdsvc.exe' - '1' Module(s) have been scanned
                          Scan process 'svcntaux.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'a2service.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                          Scan process 'ashServ.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                          Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                          Scan process 'lsm.exe' - '1' Module(s) have been scanned
                          Scan process 'lsass.exe' - '1' Module(s) have been scanned
                          Scan process 'services.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'wininit.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'smss.exe' - '1' Module(s) have been scanned
                          58 processes with 58 modules were scanned

                          Start scanning boot sectors:
                          Boot sector 'C:\'
                          [NOTE] No virus was found!
                          Boot sector 'D:\'
                          [NOTE] No virus was found!

                          Starting to scan the registry.
                          The registry was scanned ( '15' files ).

                          Starting the file scan:

                          Begin scan in 'C:\'
                          C:\hiberfil.sys
                          [WARNING] The file could not be opened!
                          C:\pagefile.sys
                          [WARNING] The file could not be opened!
                          Begin scan in 'D:\' <PRESARIO_RP>

                          End of the scan: vendredi 2 novembre 2007 02:30
                          Used time: 1:00:14 min

                          The scan has been done completely.

                          11999 Scanning directories
                          265337 Files were scanned
                          0 viruses and/or unwanted programs were found
                          0 Files were classified as suspicious:
                          0 files were deleted
                          0 files were repaired
                          0 files were moved to quarantine
                          0 files were renamed
                          2 Files cannot be scanned
                          265337 Files not concerned
                          2048 Archives were scanned
                          2 Warnings
                          61 Notes
                          1. Contributeur
                            supprime la quarantaine avant de le desinstaller, on sait jamais; comme tu me le fais remarquer...
                            1. Re G!rly,
                              Dis moi, en suprimant Avast ( avant l'installation de antivir ) que va t'il advenir des virus en quarantaine ? il n'y a aucun danger ?!
                              1. Contributeur
                                bonjour luxav,

                                oui j´ai vu l´incruste...

                                pour launcher exe ,on ne l´a pas supprimé, juste enlevé l´entrée,mais regarde ce qui suit tu comprendras pourquoi :

                                https://www.auditmypc.com/launcher.asp en anglais mais comprehenssible...

                                tu peux supprimer ot_move it, garde quand meme avg supprime spysweeper, car toute facon il est en periode d´essaie. supprime les quarantaines...

                                desinstal avast et instal antivir qui est beaucoup plus performant, tu va pouvoir faire un scan complet avec...

                                anti virus : antivir

                                http://forum.malekal.com/ftopic3528.php <- comparatif avast vs antivir

                                https://www.usitility.com/fr/avira-free-antivirus/telecharger-windows-10 <- antivir telechargement vista

                                installation antivir tutoriel :

                                https://www.malekal.com/avira-free-security-antivirus-gratuit/

                                pour le par feu zone alarm ici : https://www.zonealarm.com/

                                une fois que tu as fais tout ca , scan la totalité de ton pc avec antivir ( configure le au maximum de ces possiblités ) et post le rapport ici. (genere un rapport par defaut, c´est largement suffisant)

                                http://mickael.barroux.free.fr/securite/antivir.php <- tutoriel configuration du scanner...

                                pas facil vista ;-(

                                @+
                                1. ATTENTION G!RLY PASSE LE MESSAGE CI DESSUS QUELQU'UN A INTERFERE .... MERCI
                                  1. MSNFix 1.560

                                    C:\Documents and Settings\Utilisateur\Bureau\MSNFix
                                    Fix exécuté le 01/11/2007 - 12:10:51,60 By Utilisateur
                                    mode normal

                                    ************************ Recherche les fichiers présents

                                    ... C:\DOCUME~1\ALLUSE~1\MENUDM~1\carlton
                                    ... C:\Program Files\Fichiers communs\Carlson\carlton
                                    ... C:\er-1-1148.exe
                                    ... C:\k3d3t4t8n7l.exe
                                    ... C:\WINDOWS\LBTWiz.exe
                                    ... C:\WINDOWS\Nokia_19_jpg.zip
                                    ... C:\WINDOWS\system32\microsoft\backup.ftp
                                    ... C:\WINDOWS\system32\microsoft\backup.tftp
                                    ... C:\WINDOWS\Nokia_19_jpg.zip

                                    ************************ MSNCHK ***** /!\ beta test /!\

                                    [!] C:\WINDOWS\Nokia_19_jpg.zip is INFECTED

                                    ************************ Recherche les dossiers présents

                                    ... C:\Program Files\Fichiers communs\Carlson\

                                    ************************ Suppression des fichiers

                                    .. OK ... C:\DOCUME~1\ALLUSE~1\MENUDM~1\carlton
                                    .. OK ... C:\Program Files\Fichiers communs\Carlson\carlton
                                    .. OK ... C:\er-1-1148.exe
                                    .. OK ... C:\k3d3t4t8n7l.exe
                                    /!\ ... C:\WINDOWS\LBTWiz.exe
                                    .. OK ... C:\WINDOWS\Nokia_19_jpg.zip
                                    .. OK ... C:\WINDOWS\system32\microsoft\backup.ftp
                                    .. OK ... C:\WINDOWS\system32\microsoft\backup.tftp
                                    .. OK ... C:\k3d3t4t8n7l.exe
                                    .. OK ... C:\k3d3t4t8n7l.exe
                                    .. OK ... C:\k3d3t4t8n7l.exe
                                    .. OK ... C:\k3d3t4t8n7l.exe
                                    .. OK ... C:\WINDOWS\Nokia_19_jpg.zip

                                    ************************ Suppression des dossiers

                                    .. OK ... C:\Program Files\Fichiers communs\Carlson\

                                    ************************ Nettoyage du registre

                                    Les fichiers encore présents seront supprimés au prochain redémarrage

                                    ************************ Suppression des fichiers

                                    .. OK ... C:\WINDOWS\LBTWiz.exe

                                    ************************ Fichiers suspects

                                    Aucun Fichier trouvé

                                    Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 01112007_12172782.zip

                                    ------------------------------------------------------------------------
                                    Auteur : !aur3n7 Contact: https://www.ionos.fr/
                                    ------------------------------------------------------------------------

                                    --------------------------------------------- END ---------------------------------------------
                                    1. Bonjour,
                                      Ben en fait j'ai l'impression que c'est pire. Depuis l'installation de spysweeper il à planté 3 fois, il n'a plus voulu répondre à aucune commande ( ctrl+alt+supp )+ écran comme voilé, obligé de l'éteindre au bouton d'arret , de le débrancher ..... J''ai peur pour %windir%\sminst\launcher.exe , il a disparu des écrans radar, il n'est plus sur le rapport hijackthis est-ce que ca veut dire qu'il a été supprimé du pc ???? Je sais qu'il est trés important dans le fonctionnement de windows . P......n, je m'inquiète G!rly !!!!

                                      Ily a aussi une nouvelle icone qui est apparue sur le bureau, comme une feuille de répertoire avec pour petit nom "catchme" et pour contenu:
                                      disk not found C:\
                                      please note that you need administrator rights to perform deep scan

                                      Dis moi G!rly stp se que je dois faire de ce que j'ai installé ( AVG, OTmovelt, Spysweeper, ) et de leur contenu, que dois je garder comme antivirus ? Avast est il aussi bon qu'on le prétend ? Et que faire des virus en quarantaine ? Spyware Doctor suffit il ou dois en rajouter un? Je voulais installer Zone Alarm mais il ne fonctionne pas je crois avec cette arnaque de Vista.
                                      Sincerment désolé G!rly de te noyer de questions c'est, je te l'avoue, un peu abusé ... mais c'est l'outil de travail de ma Chérie pour réussir son master.

                                      Je te remercie encore une fois G!rly pour ta patience.
                                      J'attends ton verdict....
                                      Ci-joint rapport hijackthis.

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 12:03:30, on 01/11/2007
                                      Platform: Windows Vista (WinNT 6.00.1904)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\Windows\System32\smss.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\wininit.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\services.exe
                                      C:\Windows\system32\lsass.exe
                                      C:\Windows\system32\lsm.exe
                                      C:\Windows\system32\winlogon.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\SLsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\Windows\System32\spoolsv.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Windows Defender\MSASCui.exe
                                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                      C:\Windows\System32\igfxtray.exe
                                      C:\Windows\System32\hkcmd.exe
                                      C:\Windows\System32\igfxpers.exe
                                      C:\Program Files\HP\QuickPlay\QPService.exe
                                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                      C:\Program Files\Spyware Doctor\SDTrayApp.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Program Files\MSN Messenger\msnmsgr.exe
                                      C:\Program Files\a-squared Free\a2service.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Spyware Doctor\svcntaux.exe
                                      C:\Program Files\Spyware Doctor\swdsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\SearchIndexer.exe
                                      C:\Windows\system32\DRIVERS\xaudio.exe
                                      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe
                                      C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                                      C:\Windows\system32\conime.exe
                                      C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe

                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.finderg.com
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                      O1 - Hosts: ::1 localhost
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                                      O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
                                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
                                      O4 - HKLM\..\Run: [QlbCtrl] "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
                                      O4 - HKLM\..\Run: [HP Health Check Scheduler] "C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe"
                                      O4 - HKLM\..\Run: [WAWifiMessage] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe"
                                      O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                                      O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
                                      O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
                                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                      O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
                                      O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe" /ScheduleSweep=HPCeeScheduleForpccity
                                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                                      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                      O13 - Gopher Prefix:
                                      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                                      O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                                      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                      O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                      • 1
                                      • 2
                                      • 3
                                      • 4