excusez-moi, je voulais juste faire vite! je reprends...
j'ai chopé un vilain virus sur mon pc qui faisait que je ne pouvais plus l'éteindre. Il buggait quand je faisais éteindre l'ordinateur, je ne pouvais que fermer ma session. Je precise que je suis sous windows xp. J'ai verifier mon norton antivirus et la licence avait expiré. Du coup j'ai téléchargé antivir sur les conseils d'un pote, et je l'ai lancé. il m'a trouvé pleins de saloperies, et a nettoyé ou réparé selon les cas. J'ai ensuite fait tourner adaware. Re-nettoyage et mon pb de fermeture etait resolu. Seulement depuis je n'ai plus de connection à internet. Je suis chez noos en ethernet, j'ai verifié mon reseau (ca marche sur un autre pc) et ca vient de mon pc; j'ai le message suivant : connexion limitée ou inexistante, parce que le fournisseur d'accès ne me fournit pas d'adresse IP (paramétrée en automatique). J'ai verifié de nombreuses fois mes paramètres, activer, desactiver la carte reseau, branche un autre pc a mon modem noos qui fonctionne tres bien...
du coup j'ai fait tourné lspfix, hijackthis en fixant ce qu'on m'avait dit de fixé sur le forum pcastuce, escan et j'obtiens les logs suivantes :
escan (uniquement les lignes autres que scanning files ou folder)
Files :
Mon Feb 28 22:17:16 2005 => File C:\WINDOWS\ml-cleanup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 22:17:17 2005 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 22:17:17 2005 => File C:\WINDOWS\NDNuninstall5_48.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:17:44 2005 => File C:\WINDOWS\system32\HotParty_fr-uninstall.exe tagged as not-a-virus:RiskWare.Dialer.gen. No Action Taken.
Mon Feb 28 22:20:21 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\alkoholi.exe tagged as not-a-virus:Joke.Win32.CrazyMouse. No Action Taken.
Mon Feb 28 22:20:21 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\Cadeau.exe tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
Mon Feb 28 22:20:23 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\flipper.exe tagged as not-a-virus:Joke.BadDay. No Action Taken.
Mon Feb 28 22:20:23 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\Halowens.exe tagged as not-a-virus:Simulator.Win16.MessageMates. No Action Taken.
Mon Feb 28 22:20:24 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\metro.exe tagged as not-a-virus:Joke.Win32.RideRoof. No Action Taken.
Mon Feb 28 22:20:24 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\Mini-jupe.exe tagged as not-a-virus:Joke.Win32.Oups. No Action Taken.
Mon Feb 28 22:20:24 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\P.Goblet.exe tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
Mon Feb 28 22:20:24 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\PARKINSO.EXE infected by "not-virus:Joke.Win16.Aloap" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:20:24 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\piegates.exe tagged as not-a-virus:Game.PieGates. No Action Taken.
Mon Feb 28 22:20:25 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\Robots.exe tagged as not-a-virus:Simulator.Win16.MessageMates. No Action Taken.
Mon Feb 28 22:20:25 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\scmpoo16.exe tagged as not-a-virus:Simulator.Win16.Sheep. No Action Taken.
Mon Feb 28 22:20:25 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\Shampoo.exe tagged as not-a-virus:Simulator.Win16.Sheep. No Action Taken.
Mon Feb 28 22:20:25 2005 => Result: ERROR!!! File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\sonic2saver.exe is Not Scanned
Mon Feb 28 22:20:25 2005 => C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\sonic2saver.exe not Scanned. Possibly password protected...
Mon Feb 28 22:20:26 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\windows95.exe infected by "not-virus:Joke.Win32.Stript" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:20:26 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Divers\Affichage à l'envers.zip tagged as not-a-virus:Joke.BadDay. No Action Taken.
Mon Feb 28 22:20:30 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Divers\Virus 1.zip tagged as not-a-virus:Joke.Win16.Jeff. No Action Taken.
Mon Feb 28 22:21:59 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Programs\Emulez\Utilitaires\Extract Xiso\extract-xiso_gui_by_huge_v1.0.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 22:21:59 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Programs\Emulez\Utilitaires\FlashFXP\FlashFXP_21_Setup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 22:22:15 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Programs\FlashFXP_21_Setup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 22:22:51 2005 => File C:\Documents and Settings\Jay\Mes documents\Downloads\Programs\susetup.exe tagged as not-a-virus:RiskWare.FTP.Serv-U.50011. No Action Taken.
Mon Feb 28 22:26:59 2005 => File C:\Hijackthis\backups\backup-20050228-213438-968 infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:26:59 2005 => File C:\Hijackthis\hijackthis1.log infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:27:04 2005 => File C:\Program Files\Admilli Service\AdmilliComm.dll infected by "not-a-virus:AdWare.WinAD.k" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:35:17 2005 => File C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.d" Virus. Action Taken: No Action Taken.
on Feb 28 22:35:17 2005 => File C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE infected by "not-a-virus:AdWare.ToolBar.MyWebSearch" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:35:17 2005 => File C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL infected by "not-a-virus:AdWare.ToolBar.MyWebSearch" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:35:19 2005 => File C:\Program Files\NewDotNet\newdotnet5_48.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:35:19 2005 => File C:\Program Files\NewDotNet\uninstall5_48.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:36:18 2005 => File C:\Program Files\SearchRelevant\SearchRelevant.dll infected by "not-a-virus:AdWare.Relevance.c" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:48:05 2005 => File C:\RECYCLER\S-1-5-21-774114920-3893239111-1490783594-1005\Dc13.log infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:49:15 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP279\A0070317.dll infected by "Email-Worm.Win32.Tanatos.b.dam2" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:49:20 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP279\A0070490.dll infected by "not-a-virus:AdWare.Relevance.b" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:49:23 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP281\A0070504.dll infected by "not-a-virus:AdWare.Relevance.c" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:49:23 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP281\A0070506.dll infected by "Email-Worm.Win32.Tanatos.b.dam2" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:50:13 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP284\A0071471.exe infected by "not-a-virus:AdWare.WinAD.k" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:51:24 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP288\A0075105.dll infected by "Backdoor.Win32.Magicon.d" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:51:25 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP288\A0075123.exe infected by "not-a-virus:AdWare.WinAD.s" Virus. Action Taken: No Action Taken.
Mon Feb 28 22:52:44 2005 => File C:\System Volume Information\\_restore{F2D15CAD-879E-44AA-AACE-2505A1E12FC2}\RP292\A0077499.dll infected by "not-a-virus:AdWare.WinAD.u" Virus. Action Taken: No Action Taken.
Mon Feb 28 23:05:08 2005 => File C:\WINDOWS\ml-cleanup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 23:05:08 2005 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Mon Feb 28 23:05:10 2005 => File C:\WINDOWS\NDNuninstall5_48.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken.
Mon Feb 28 23:10:38 2005 => File C:\WINDOWS\system32\HotParty_fr-uninstall.exe tagged as not-a-virus:RiskWare.Dialer.gen. No Action Taken.
ERROR:
Mon Feb 28 22:15:52 2005 => ERROR!!! Invalid Entry \??\C:\DOCUME~1\Jay\LOCALS~1\Temp\asbp2poa.sys. Removing SYSTEM\CurrentControlSet\Services\asbp2poa...
Mon Feb 28 22:20:25 2005 => Result: ERROR!!! File C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\sonic2saver.exe is Not Scanned
Mon Feb 28 22:20:25 2005 => C:\Documents and Settings\Jay\Mes documents\Downloads\Mails\Applications\sonic2saver.exe not Scanned. Possibly password protected...
Mon Feb 28 22:20:58 2005 => Result: ERROR!!! File C:\Documents and Settings\Jay\Mes documents\Downloads\Programs\aawsepersonal.exe is Not Scanned
Mon Feb 28 22:20:58 2005 => C:\Documents and Settings\Jay\Mes documents\Downloads\Programs\aawsepersonal.exe not Scanned. Possibly password protected...
Mon Feb 28 22:27:00 2005 => Result: ERROR!!! File C:\pagefile.sys: Scanning Failure!!!
Mon Feb 28 22:27:00 2005 => ERROR!!! ScanFile fails for C:\pagefile.sys
Mon Feb 28 22:32:25 2005 => Result: ERROR!!! File C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask is Not Scanned
Mon Feb 28 22:32:25 2005 => C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask not Scanned. Possibly password protected...
et la log hijackthis juste après :
Logfile of HijackThis v1.99.1
Scan saved at 23:21:36, on 28/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\vaio media music server\SSSvr.exe
C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Apps\Updater\\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.sony-europe.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\\01.02.3000.1001\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\\01.02.3000.1001\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\vaio media platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Fichiers communs\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Fichiers communs\sony shared\vaio media platform\UPnPFramework.exe
si vous avez d'autres questions n'hesitez pas! j'espere que c assez clair...