Virus WIN32: OnLineGames

Résolu
Bonjour,

Un virus circule ds ma promo.
Mon antivirus avast a détecté un cheval de troie (WIN 32 : OnLineGames - CVP [Trj]). Je l'ai mis en quarantaine, mais je l'ai toujours car quand je vais ds poste de travail, sur le disque dur C, j'ai un message sur un logiciel malveillant. Le virus est ds le système windows. Je sais que les autres de ma promo ont eu plusieurs fichiers infectés par WIN 32.

J'ai besoin d'aide.

Merci d'avance
Configuration: Windows XP
Internet Explorer 6.0

31 réponses

Résumé de la discussion

Un virus circule dans la promotion et Avast détecte un cheval de Troie (WIN32:OnLineGames CVP [Trj]); la quarantaine est appliquée mais un message malveillant persiste sur le disque C. Plusieurs intervenants proposent des solutions techniques incluant des outils de détection et de suppression comme HijackThis et ComboFix, et des conseils pour installer un antivirus alternatif tel qu'Antivir. Des conseils couvrent aussi la désactivation temporaire de la restauration système, l'analyse complète du disque et le post-traitement avec des rapports détaillés issus de scans, afin d'assurer l'élimination des éléments malveillants. En fin de fil, les messages partagent des rapports d'analyse et des extraits de journaux pour vérifier que les services et fichiers indésirables ont été supprimés et que le système est propre.

Bobot (l’IA à votre service)
  1. Contributeur
    De rien ;-)

    A jamais`
    0
    1. Merci beaucoup pour tout !

      J'espère que j'aurai plus besoin de toi à partir de maintenant !! ;-)

      Bonne soirée
      Bye
      0
      1. Contributeur
        ok morganne de toi 3333 ;-)

        nos chemins se separent ici...

        Bonne soirée/continuation`

        Bye`

        g!rly`
        0
        1. -->- Recherche:

          C:\Combofix: trouvé !
          C:\Qoobox: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
          C:\Documents and Settings\acer\Bureau\HijackThis.lnk: trouvé !
          C:\Documents and Settings\acer\Bureau\PB WIN 32\ComboFix.exe: trouvé !
          C:\Documents and Settings\acer\Bureau\PB WIN 32\HJTInstall.exe: trouvé !
          C:\Program Files\Trend Micro\HijackThis: trouvé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
          C:\QooBox\Quarantine\C\Combofix: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
          C:\Documents and Settings\acer\Bureau\HijackThis.lnk: supprimé !
          C:\Documents and Settings\acer\Bureau\PB WIN 32\ComboFix.exe: supprimé !
          C:\Documents and Settings\acer\Bureau\PB WIN 32\HJTInstall.exe: supprimé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
          C:\Combofix: supprimé !
          C:\Qoobox: supprimé !
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
          C:\Program Files\Trend Micro\HijackThis: supprimé !
          0
          1. Contributeur
            ok ;-)

            fais ceci :

            Désactive ta restauration système:
            pour cela :
            Click droit sur poste de travail, dans l´arborescence sur propriétés;
            dans la nouvelle fenettre click sur l´onglet restauration système;
            coche la case désactiver la restauration systèm et applique.
            puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
            dans la nouvelle fenettre click sur l´onglet restauration systèm
            décoche la case désactiver la restauration systèm et applique.

            puis

            Télécharge ToolsCleaner sur ton bureau.
            --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
            # Clique sur Recherche et laisse le scan agir ...
            # Clique sur Suppression pour finaliser.
            # Tu peux, si tu le souhaites, te servir des Options facultatives.
            # Clique sur Quitter pour obtenir le rapport.
            # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

            @+
            0
            1. Contributeur
              ok morgane3333

              plus de doute de ce coté la ;-)

              comment va ton pc ?

              @+
              0
              1. Nouveau rapport :

                C:\autorun.inf Non trouvé
                C:\MS32DLL.dll.vbs Non trouvé
                D:\autorun.inf Non trouvé
                D:\MS32DLL.dll.vbs Non trouvé
                F:\autorun.inf Non trouvé
                F:\MS32DLL.dll.vbs Non trouvé
                G:\autorun.inf Non trouvé
                G:\MS32DLL.dll.vbs Non trouvé
                C:\WINDOWS\MS32DLL.dll.vbs non trouvé

                ! REG.EXE VERSION 3.0

                HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
                LaunchApp REG_SZ
                ATICCC REG_SZ "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                AzMixerSel REG_SZ C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                PCMService REG_SZ "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
                ntiMUI REG_SZ C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                Acer ePresentation HPD REG_SZ C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
                MSPY2002 REG_SZ C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                PHIME2002ASync REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                PHIME2002A REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                ePower_DMC REG_SZ C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
                Boot REG_SZ C:\Acer\Empowering Technology\ePower\Boot.exe
                RTHDCPL REG_SZ RTHDCPL.EXE
                SkyTel REG_SZ SkyTel.EXE
                SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                LManager REG_SZ C:\PROGRA~1\LAUNCH~1\LManager.exe
                eRecoveryService REG_SZ C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                avgnt REG_SZ "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

                HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

                ! REG.EXE VERSION 3.0

                HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
                CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
                MsnMsgr REG_SZ "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                Rainlendar2 REG_SZ C:\Program Files\Rainlendar2\Rainlendar2.exe
                BitComet REG_SZ "C:\Program Files\BitComet\BitComet.exe" /tray
                0
                1. Contributeur
                  morganne333,

                  les par feu sont equivalent, sauf zone alarm qui est un peu moins perforamant, moi j´ai kerio...

                  ok pour malwarebytes ;-)

                  fais ceci pour verifier un truc :

                  Ouvre le bloc notes (Démarrer >> exécuter et tape notepad), et copie tout ce qui ci-dessous:

                  @ echo off

                  if exist \G!RLY.TXT del \G!RLY.TXT
                  FOR %%A in (C D E F G H I J K L M N O P Q R S T U V W X Y Z) DO IF EXIST %%A: (
                  IF EXIST %%A:\autorun.inf ECHO %%A:\autorun.inf Présent>>\G!RLY.TXT
                  IF NOT EXIST %%A:\autorun.inf ECHO %%A:\autorun.inf Non trouvé>>\G!RLY.TXT
                  IF EXIST %%A:\MS32DLL.dll.vbs ECHO %%A:\MS32DLL.dll.vbs Présent>>\G!RLY.TXT
                  IF NOT EXIST %%A:\MS32DLL.dll.vbs ECHO %%A:\MS32DLL.dll.vbs Non trouvé>>\G!RLY.TXT
                  )
                  IF EXIST %WINDIR%\MS32DLL.dll.vbs (
                  ECHO %WINDIR%\MS32DLL.dll.vbs Présent>>\G!RLY.TXT) else (
                  ECHO %WINDIR%\MS32DLL.dll.vbs non trouvé >>\G!RLY.TXT)
                  REG QUERY "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" >>\G!RLY.TXT
                  REG QUERY "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" >>\G!RLY.TXT
                  notepad \G!RLY.TXT
                  exit

                  Dans le menu du bloc notes, clic sur "Fichier" >> Enregistrer sous.
                  Choisis le bureau comme lieu d'enregistrement, puis dans:

                  Type -> choisis "tous les fichiers"
                  Nom du fichier -> tape G!RLY.bat
                  clic sur enregistrer.

                  Sur ton bureau tu auras maintenant un fichier nommé G!RLY.bat.

                  Connecte les périphériques externes susceptibles d'avoir été infectés au pc:
                  Clé USB, DD externe... etc

                  Puis une fois fait, double clic sur le fichier G!RLY.bat.
                  Une fenêtre noire va s'ouvrir et se refermer rapidement, c'est normal.
                  Le bloc note va s'ouvrir ensuite avec le listing des fichiers que le script aura détecté.
                  Copie et colle ici le contenu de ce rapport.

                  @´+
                  0
                  1. Il me reste encore le pare-feu à installer : t'en as mis 3; ils sont tous équivalents niveau performance ? jvè installer le 1er !

                    Sinon, voilà le rapport demandé :

                    Malwarebytes' Anti-Malware 1.08
                    Version de la base de données: 499

                    Type de recherche: Examen complet (C:\|D:\|F:\|G:\|)
                    Eléments examinés: 84977
                    Temps écoulé: 31 minute(s), 25 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 0

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    (Aucun élément nuisible détecté)
                    0
                    1. J'ai mis la nouvelle version d'internet.

                      J'ai réinstallé antivir (mise à jour, scanner résident OK) et je l'ai configuré comme tu l'avais indiqué.

                      J'ai fait un scan complet de l'ordi : 4 détections et 2 fichiers qui n'ont pas pu être scannés !

                      Je mets le rapport :

                      AntiVir PersonalEdition Classic
                      Report file date: lundi 17 mars 2008 20:21

                      Scanning for 1150818 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Username: SYSTEM
                      Computer name: ACER-318DE0055E

                      Version information:
                      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:30
                      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:52
                      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:48
                      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:22
                      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:16
                      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 19:09:38
                      ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 19:09:38
                      ANTIVIR3.VDF : 7.0.3.41 197632 Bytes 17/03/2008 19:09:38
                      AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 17/03/2008 19:09:38
                      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:28
                      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:18
                      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                      AVPACK32.DLL : 7.6.0.3 360488 Bytes 17/03/2008 19:09:38
                      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:08
                      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:34
                      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:20
                      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:44
                      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:14
                      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:38
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:22

                      Configuration settings for the scan:
                      Jobname..........................: Complete system scan
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: D:,
                      Scan memory......................: on
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: on
                      Scan all files...................: All files
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: high

                      Start of the scan: lundi 17 mars 2008 20:21

                      Starting search for hidden objects.
                      '42026' objects were checked, '0' hidden objects were found.

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'hpqSTE08.exe' - '1' Module(s) have been scanned
                      Scan process 'CLI.EXE' - '1' Module(s) have been scanned
                      Scan process 'CLI.EXE' - '1' Module(s) have been scanned
                      Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                      Scan process 'Acer.Empowering.Framework.Launcher.exe' - '1' Module(s) have been scanned
                      Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                      Scan process 'Rainlendar2.exe' - '1' Module(s) have been scanned
                      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                      Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                      Scan process 'eRAgent.exe' - '1' Module(s) have been scanned
                      Scan process 'LManager.exe' - '1' Module(s) have been scanned
                      Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                      Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
                      Scan process 'ePower_DMC.exe' - '1' Module(s) have been scanned
                      Scan process 'PCMService.exe' - '1' Module(s) have been scanned
                      Scan process 'CLI.EXE' - '1' Module(s) have been scanned
                      Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                      Scan process 'alg.exe' - '1' Module(s) have been scanned
                      Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
                      Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
                      Scan process 'CLSched.exe' - '1' Module(s) have been scanned
                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                      Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
                      Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                      Scan process 'CLMLService.exe' - '1' Module(s) have been scanned
                      Scan process 'CLMLServer.exe' - '1' Module(s) have been scanned
                      Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                      Scan process 'MemCheck.exe' - '1' Module(s) have been scanned
                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                      Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
                      Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
                      Scan process 'ATI2EVXX.EXE' - '1' Module(s) have been scanned
                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                      Scan process 'ATI2EVXX.EXE' - '1' Module(s) have been scanned
                      Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
                      Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
                      Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
                      Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
                      Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
                      48 processes with 48 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [NOTE] No virus was found!

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [NOTE] No virus was found!
                      Boot sector 'D:\'
                      [NOTE] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '46' files ).

                      Starting the file scan:

                      Begin scan in 'C:\' <ACER>
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      C:\hiberfil.sys
                      [WARNING] The file could not be opened!
                      Begin scan in 'D:\' <ACERDATA>
                      D:\xpbkh.com
                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                      [INFO] The file was deleted!
                      D:\y82td3td.com
                      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
                      [INFO] The file was moved to '4810c978.qua'!
                      D:\System Volume Information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP8\A0000519.com
                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                      [INFO] The file was moved to '480ec97f.qua'!
                      D:\System Volume Information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP8\A0000520.com
                      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
                      [INFO] The file was moved to '480ec982.qua'!

                      End of the scan: lundi 17 mars 2008 20:48
                      Used time: 27:18 min

                      The scan has been done completely.

                      4272 Scanning directories
                      216684 Files were scanned
                      4 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      1 files were deleted
                      0 files were repaired
                      3 files were moved to quarantine
                      0 files were renamed
                      2 Files cannot be scanned
                      216680 Files not concerned
                      6519 Archives were scanned
                      2 Warnings
                      0 Notes
                      42026 Objects were scanned with rootkit scan
                      0 Hidden objects were found
                      0
                      1. Contributeur
                        re,

                        ok il se peux qu´antivir n´arrivait pas a se mettre a jour, dis moi si il y arrive maintenant une fois installé...

                        @+
                        0
                        1. OK OK, jvais regarder tout ça !

                          Mais, pr l'antivirus, g une explication !! j'avais des messages comme koi je n'avais pas d'antivirus sur mon ordi (alors que c juste parce que je n'avais pas configurer le scanner résident; débile oui, ms on va dire que j'étais fatiguée !!!)

                          Bon, jvè désinstaller avast et remettre antivir (au fait, les fichiers qui étaient en quarantaine sur avast, ils deviennent koi ??).

                          Après,jvè regarder cke t'a mis. Ouais, pr la version internet, ça m'étonne pas. J'avais mis firefox, mais g eu un pb ac ma carte mère qui a été changée y a tout juste deux semaines, c pr ça : g pas eu l tps de réinstaller les bons trucs avant d'avoir un virus !!
                          0
                          1. Contributeur
                            morganne3333,

                            fais ceci :

                            tu surf avec internet explorer 6.0 = failles de securitées importantes

                            alors fais les mises a jour windows : tu veux la version 7.0

                            https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70

                            et pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

                            http://www.mozilla-europe.org/fr/

                            plugins : je te comseil ad block plus

                            https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

                            puis

                            ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

                            et instale la derniere :

                            https://get2.adobe.com/reader/otherversions/

                            ou oublie completement acrobat reader et instales foxit plus léger a la place:

                            https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

                            instales un par feu .

                            par feu : kerio

                            telechargement : http://sd-1.archive-host.com/membres/up/1366464061/kerio-kpf-422-911-win.rar

                            tuto :

                            http://www.malekal.com/kerio_firewall.php#mozTocId721480

                            https://www.vulgarisation-informatique.com/kerio.php

                            https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                            Comodo 3 pro :

                            http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

                            Online armor :

                            http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

                            tuto : https://forum.pcastuces.com/sujet.asp?f=25&s=35606

                            ou zone alarm plus facil a configurer mais moins performant

                            https://www.malekal.com/tutoriel-zonealarm-firewall/

                            bonus :

                            anti spyware :

                            spywareblaster :

                            http://www.brightfort.com/spywareblaster.html

                            c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                            tuto : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/question-spywareblaser-sujet_174747_1.htm

                            puis quelle idée d´avoir remis avast qu´est ce qui n´allait pas avec antivir ?

                            desinstales avast et remets antivir et dis moi

                            passe aussi cet anti spyware .

                            telecharge malwarebytes

                            -> http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/anti-malware-sujet_197382_1.htm

                            tu l´instales, le programme va se mettre a jour automatiquement.

                            une fois a jour le programme va se lancer, clcik sur l´onglet parametre, tu coche la case : Arreter internet explorer pendant la suppression.

                            click sur l´onglet recherche maintenant et coche la case : executer un examun complet.

                            puis click sur rechercher.

                            laisses le scanner le pc, a la fin un rapport va s´ouvrir copie et colle le ici stp

                            @+
                            0
                            1. Ok, j'ai faitce que tu m'as dit.
                              Et je t'envoie le scan hijackthis.

                              (juste pr info, j'avais mal installé antivir je crois, dc je l'ai plus, tjs avast, ms il faut que je le remette)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 13:40:07, on 17/03/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                              C:\Program Files\Acer\Acer Arcade\PCMService.exe
                              C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
                              C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\PROGRA~1\LAUNCH~1\LManager.exe
                              C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\MSN Messenger\MsnMsgr.Exe
                              C:\Program Files\Rainlendar2\Rainlendar2.exe
                              C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                              C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                              C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
                              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\WINDOWS\system32\wbem\unsecapp.exe
                              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                              O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
                              O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                              O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
                              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                              O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
                              O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
                              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                              O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                              O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
                              O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: Acer Empowering Technology.lnk = ?
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                              O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://mlcmoa.spaces.live.com/PhotoUpload/MsnPUpld.cab
                              O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              0
                              1. Contributeur
                                Morgane3333,

                                excuse, je ne reponds que maintenant,

                                tous les fichiers present dans le rapport de scan d´antivir sont soit dans la quarantaine de combofix soit dans la restauration system qui a ete touché...

                                fais ceci :

                                Désactive ta restauration système:
                                pour cela :
                                Click droit sur poste de travail, dans l´arborescence sur propriétés;
                                dans la nouvelle fenettre click sur l´onglet restauration système;
                                coche la case désactiver la restauration systèm et applique.
                                puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
                                dans la nouvelle fenettre click sur l´onglet restauration systèm
                                décoche la case désactiver la restauration systèm et applique.

                                post un dernier hijack this stp

                                dis moi quoi

                                @+
                                0
                                1. Si qqn a des idées pour mon pb de virus, ce serait bien sympa de me les donner !!!

                                  MERCI
                                  0
                                  1. Contributeur
                                    Ok ca marche morgane,

                                    @+
                                    0
                                    1. Salut

                                      J'ai toujours des virus, au secours !
                                      Je n'avais plus rien, ms qd je suis retournée sur internet hier pr télécharger antivir, un cheval de troie a été détecté.
                                      J'ai ensuite fait un scan ac antivir et il m'a détecté pls fichiers infectés. C toujours WIN 32.

                                      Je sais plus comment faire !!
                                      Merci de m'aider

                                      SCAN ANTIVIR :

                                      AntiVir PersonalEdition Classic
                                      Report file date: jeudi 13 mars 2008 18:22

                                      Scanning for 835736 virus strains and unwanted programs.

                                      Licensed to: Avira AntiVir PersonalEdition Classic
                                      Serial number: 0000149996-ADJIE-0001
                                      Platform: Windows XP
                                      Windows version: (Service Pack 2) [5.1.2600]
                                      Username: SYSTEM
                                      Computer name: ACER-318DE0055E

                                      Version information:
                                      BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                                      AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:30
                                      AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:52
                                      LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:48
                                      LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:22
                                      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:16
                                      ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:56
                                      ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 14:27:04
                                      ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 14:27:14
                                      AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 17:43:56
                                      AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:28
                                      AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:18
                                      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                                      AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:02
                                      AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:08
                                      AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:34
                                      AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:20
                                      NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:44
                                      RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:14
                                      RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:38
                                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:22

                                      Configuration settings for the scan:
                                      Jobname..........................: Complete system scan
                                      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                      Logging..........................: low
                                      Primary action...................: interactive
                                      Secondary action.................: ignore
                                      Scan master boot sector..........: on
                                      Scan boot sector.................: on
                                      Boot sectors.....................: D:,
                                      Scan memory......................: on
                                      Process scan.....................: on
                                      Scan registry....................: on
                                      Search for rootkits..............: on
                                      Scan all files...................: All files
                                      Scan archives....................: on
                                      Recursion depth..................: 20
                                      Smart extensions.................: on
                                      Macro heuristic..................: on
                                      File heuristic...................: high

                                      Start of the scan: jeudi 13 mars 2008 18:22

                                      Starting search for hidden objects.
                                      '44212' objects were checked, '0' hidden objects were found.

                                      The scan of running processes will be started
                                      Scan process 'WINWORD.EXE' - '1' Module(s) have been scanned
                                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                                      Scan process 'ashWebSv.exe' - '1' Module(s) have been scanned
                                      Scan process 'ashMaiSv.exe' - '1' Module(s) have been scanned
                                      Scan process 'avconfig.exe' - '1' Module(s) have been scanned
                                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                                      Scan process 'notepad.exe' - '1' Module(s) have been scanned
                                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                                      Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'CLI.EXE' - '1' Module(s) have been scanned
                                      Scan process 'CLI.EXE' - '1' Module(s) have been scanned
                                      Scan process 'ALG.EXE' - '1' Module(s) have been scanned
                                      Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                                      Scan process 'WMIAPSRV.EXE' - '1' Module(s) have been scanned
                                      Scan process 'hpqSTE08.exe' - '1' Module(s) have been scanned
                                      Scan process 'WMIPRVSE.EXE' - '1' Module(s) have been scanned
                                      Scan process 'WMIPRVSE.EXE' - '1' Module(s) have been scanned
                                      Scan process 'CLSched.exe' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
                                      Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                                      Scan process 'CLMLService.exe' - '1' Module(s) have been scanned
                                      Scan process 'CLMLServer.exe' - '1' Module(s) have been scanned
                                      Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
                                      Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                                      Scan process 'Acer.Empowering.Framework.Launcher.exe' - '1' Module(s) have been scanned
                                      Scan process 'MemCheck.exe' - '1' Module(s) have been scanned
                                      Scan process 'Rainlendar2.exe' - '1' Module(s) have been scanned
                                      Scan process 'MSNMSGR.EXE' - '1' Module(s) have been scanned
                                      Scan process 'CTFMON.EXE' - '1' Module(s) have been scanned
                                      Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                                      Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
                                      Scan process 'eRAgent.exe' - '1' Module(s) have been scanned
                                      Scan process 'LManager.exe' - '1' Module(s) have been scanned
                                      Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                                      Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
                                      Scan process 'ePower_DMC.exe' - '1' Module(s) have been scanned
                                      Scan process 'PCMService.exe' - '1' Module(s) have been scanned
                                      Scan process 'SPOOLSV.EXE' - '1' Module(s) have been scanned
                                      Scan process 'CLI.EXE' - '1' Module(s) have been scanned
                                      Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
                                      Scan process 'ashServ.exe' - '1' Module(s) have been scanned
                                      Scan process 'ATI2EVXX.EXE' - '1' Module(s) have been scanned
                                      Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
                                      Scan process 'ATI2EVXX.EXE' - '1' Module(s) have been scanned
                                      Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
                                      Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
                                      Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
                                      Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
                                      60 processes with 60 modules were scanned

                                      Starting master boot sector scan:
                                      Master boot sector HD0
                                      [NOTE] No virus was found!

                                      Start scanning boot sectors:
                                      Boot sector 'C:\'
                                      [NOTE] No virus was found!
                                      Boot sector 'D:\'
                                      [NOTE] No virus was found!

                                      Starting to scan the registry.
                                      The registry was scanned ( '47' files ).

                                      Starting the file scan:

                                      Begin scan in 'C:\' <ACER>
                                      C:\pagefile.sys
                                      [WARNING] The file could not be opened!
                                      C:\hiberfil.sys
                                      [WARNING] The file could not be opened!
                                      C:\QooBox\Quarantine\C\b.com.vir
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '483c6871.qua'!
                                      C:\QooBox\Quarantine\C\xpbkh.com.vir
                                      [DETECTION] Contains suspicious code HEUR/Crypted
                                      [INFO] The file was moved to '483b68b9.qua'!
                                      C:\QooBox\Quarantine\C\y82td3td.com.vir
                                      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
                                      [INFO] The file was moved to '480b6884.qua'!
                                      C:\QooBox\Quarantine\C\WINDOWS\system32\amvo.exe.vir
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '484f68bd.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003550.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '48096886.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003597.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '4809688a.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003631.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '4809688d.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003661.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '48096890.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003669.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '48096892.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003699.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '48096894.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003703.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '48096896.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003736.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '4809689a.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004456.DLL
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '4809689b.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003740.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '4809689d.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003770.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '4809689f.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003776.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968a2.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003821.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968ac.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003825.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968ae.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003878.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968b0.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003882.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968b2.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003913.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968b4.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003917.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968b7.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003960.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968b9.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003964.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968bb.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0003995.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968bd.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004008.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968bf.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004046.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968c2.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004052.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968c4.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004075.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968c7.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004085.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968ca.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004089.exe
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968cf.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004090.exe
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968d0.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004237.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
                                      [INFO] The file was moved to '480968d3.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004239.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968d5.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004483.exe
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968d7.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004262.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968de.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004277.dll
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [INFO] The file was moved to '480968e1.qua'!
                                      C:\system volume information\_restore{114BBA23-0C1A-4D24-8D0F-D4F7325498E1}\RP21\A0004287.com
                                      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                                      [WARNING] The file was ignored!

                                      End of the scan: jeudi 13 mars 2008 18:47
                                      Used time: 25:12 min

                                      4353 Scanning directories
                                      148024 Files were scanned
                                      37 viruses and/or unwanted programs were found
                                      1 Files were classified as suspicious:
                                      0 files were deleted
                                      0 files were repaired
                                      37 files were moved to quarantine
                                      0 files were renamed
                                      2 Files cannot be scanned
                                      147987 Files not concerned
                                      6300 Archives were scanned
                                      3 Warnings
                                      0 Notes
                                      44212 Objects were scanned with rootkit scan
                                      0 Hidden objects were found
                                      0
                                  2. OK, je ferais un scan entier avec antivir (par contre, j pourrais le faire que demain ou même après demain; dès que je l'aurais fait, je mettrais le rapport à la suite de cette conversation, dc qd tu pourras regarder tu me diras).

                                    En tout cas, merci pr tout.

                                    Et à la prochaine pr ce fameux rapport antivir !!

                                    Bye
                                    0
                                    1. Contributeur
                                      re,

                                      c´est ok rav antivirus a supprimé les virus ;-)

                                      pour verifier que tout est ok fais ceci :

                                      regarde ceci concernant avast :

                                      antivir vs avast :

                                      -> http://forum.malekal.com/ftopic3528.php

                                      alors je te conseille de le desinstaller et d´installer antivir a la place

                                      Telecharge et instales l'antivirus Antivir Personal Edition Classic :

                                      ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

                                      https://www.avira.com/en/prime

                                      http://mickael.barroux.free.fr/securite/antivir.php
                                      http://speedweb1.free.fr/frames2.php?page=tuto5
                                      <- tutoriel configuration du scanner...

                                      une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                                      puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                                      coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                                      puis sur la droite coche les case suivantes :
                                      scan boot sectors of selected drives
                                      scan master boot sectors
                                      scan memory
                                      search foe rootkit before scan
                                      decoche :
                                      ignore off line files
                                      toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                                      Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

                                      @+
                                      0
                                      • 1
                                      • 2