-
Compteur de contenus
64 -
Inscription
-
Dernière visite
Tout ce qui a été posté par ange1402
-
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
re voilà encore 3 dont les noms que tu m'as cité mais je les trouve nul part!! ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Tuesday, August 16, 2005 02:06:32 Operating System: Microsoft Windows XP Professional, (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 16/08/2005 Kaspersky Anti-Virus database records: 135358 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - Folders: C:\ Scan Statistics: Total number of scanned objects: 24513 Number of viruses found: 3 Number of infected objects: 3 Number of suspicious objects: 0 Duration of the scan process: 1327 sec Infected Object Name - Virus Name C:\WINDOWS\mcsecure.exe Infected: Backdoor.Win32.SdBot.aad C:\WINDOWS\system32\hpdriver.sys Infected: Rootkit.Win32.Agent.ae C:\WINDOWS\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab Scan process completed. -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
RE Je suis en train de refaire un scane kaspersky il n'est pas fini et les dossier que tu m'as cité ben vois tu je les est vus toute la journée j'ai pas arrêté de les suprimer mais ils revenais tout le temps et là ils n'y sont plus quand je fais recherche. En se qui concerne le par feux j'en ai un je comprend pas pourkoi il ne se vois pas pourtant y'a bien un cadena quand je vais voir les connections, et pour le pack 2 il ne veut pas me le prendre en compte l'instalation est un échec voilà en gros. je poste celui ci et kaspersky est à 83%apparement il reste un virus pour l'instant je sais pas encore quoi je dornerai la suite dans 5 minutes -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
j'ai remonter le poste car je savais pas si vous l'aviez vu après que j'ai fait le ménages bisous:D -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
coucu me revoilà alors là chapeau ça fait du vide grave j'ai tut fais par contre pour cleaner euh je dois enlever quoi oui oui je sais moi nul. Cependant j'ai viré norman et opistat enlevé les sevirce et voilà le bilan y'a t'il encore des méchants? merci mille fois si je peut aiser à mon tour je le ferai avec plaisir je viendrai ici régulièrement . Logfile of HijackThis v1.99.1 Scan saved at 01:19:23, on 16/08/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\Explorer.EXE C:\Documents and Settings\Angelique\Mes documents\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Program Files\OpenOffice.org1.1.4\program\quickstart.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe bisous -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
je repond avant de passé en mode sans échec , mon par feu il devrait y être bizard ça se trouve je les mal configuré . bise -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
coucou alors pour : C:\Program Files\OpiStat\OpiStat\OpiStat.exeben en faite c'est quand j'ai instaler norman mon anti virus il fallais s'inscrire là pour avoir l'anti virus c'étais une condition pour l'avoir gratuitement. Sinon est ce que Anti vir je peut le garder est ce tout le temps gratuit? Ben sinon merci beaucoup pour votre boulot ça doit pas être rose tout les jours cependant je vais essayer de bien comprendre tout ça et y' aller à mon rythme car je voudrais pas faire encore plus de bêtises. Voilà encore merci beaucoup j'aimerai bein pourvoir aider comme vous le faites. Bisous -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
re moi voilà le dernier rapport d'antivir et il ne detecte plus rien bizard je vais faire un autre avec norman bisous Creation date of the report file: lundi 15 août 2005 23:22 AntiVir®/XP (2000 + NT) PersonalEdition Classic Build 1047 vom 07.06.2005 Mainprogram 6.31.00.03 of 10.05.2005 VDF file 6.31.1.117 (0) of 15.08.2005 This program is for PERSONAL USE only. Any other use is PROHIBITED. Informations regarding commercial versions of AntiVir may be obtained from: www.hbedv.com. Scanning for 201577 virus strains and unwanted programs. Licensed for: AntiVir Personal Edition Serial number: 0000149996-WURGE-0001 Please enter the workstation and contact name with phone number in this form: Name ___________________________________________ Street ___________________________________________ Town ___________________________________________ Phone/Fax ___________________________________________ Email ___________________________________________ Platform: Windows NT Workstation Windows version: 5.1 Build 2600 () Username: Angelique Processor: Pentium Working memory: 196080 KB free Version information: AVWIN.DLL : 6.31.00.03 561192 10.05.2005 16:50:16 AVEWIN32.DLL : 6.31.1.0 823808 19.07.2005 17:54:12 AVGNT.EXE : 6.31.00.01 168039 10.05.2005 16:50:16 AVGUARD.EXE : 6.31.00.01 238120 29.04.2005 08:07:12 GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 11:24:10 AVGCMSG.DLL : 6.31.00.00 295029 29.04.2005 08:07:16 AVGNTDW.SYS : 6.31.00.01 32896 29.04.2005 08:07:16 AVPACK32.DLL : 6.31.00.03 323664 25.05.2005 10:43:02 AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 18:10:20 AVWIN.DLL : 6.31.00.03 561192 10.05.2005 16:50:16 AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 18:10:22 AVSched32.EXE : 6.30.00.00 110632 01.02.2005 11:24:10 AVSched32.DLL : 6.30.00.00 122880 01.02.2005 11:24:10 AVREG.DLL : 6.30.00.03 41000 10.02.2005 18:47:48 AVRep.DLL : 6.31.01.110 1282088 15.08.2005 07:48:40 INETUPD.EXE : 6.31.00.02 249915 29.04.2005 08:07:14 INETUPD.DLL : 6.31.00.02 143360 29.04.2005 08:07:14 CTL3D32.DLL : 2.31.000 27136 28.08.2001 14:00:00 MFC42.DLL : 6.00.8665.0 995383 28.08.2001 14:00:00 MSVCRT.DLL : 7.0.2600.0 (xpclient.010817-1148 MSVCRT.DLL : 7.0.2600.0 (xp 322560 28.08.2001 14:00:00 CTL3DV2.DLL : No information Configuration file: Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG Start path: C:\Program Files\AVPersonal Command line: Start mode: unknown Mode of report file: [ ] Do not create report [X] Overwrite report [ ] Append new report Data in report file: [X] Infected files [ ] Infected files with paths [ ] All scanned files [ ] Full information Abridge report file: [ ] Abridge report file Warnings in report: [X] Access denied/file locked [X] Wrong file size in directory [X] Wrong creation time in directory [ ] COM file is too large [X] Invalid start address [X] Invalid EXE header [X] Possibly damaged Summary report: [X] Create summary report Output file: AVWIN.ACT Maximum number of entries: 100 Where to search: [X] Memory [X] Boot record of selected drives [ ] Report unknown boot sectors [X] All files [ ] Program files Response in case of a detection: [X] Repair with prompt [ ] Repair without prompt [ ] Delete with prompt [ ] Delete without prompt [ ] Write in report file only [X] Acoustic alarm Response in case of destroyed files: [X] Delete with prompt [ ] Delete without prompt [ ] Ignore Response in case of destroyed files: [X] No change [ ] Current system time [ ] Correct date Drag&drop settings: [X] Scan subdirectories Profile settings: [X] Scan subdirectories Archive options [X] Search archive [X] Archive types to leave out 1002 1001 1000 Miscellaneous options: Temporary path: %TEMP% -> C:\Program Files\AVPersonal\BUILD.DAT [X] Overwrite infected files [ ] Detect idle time [X] Allow interruptions of scan [X] Load AVWin®/NT Guard on System start General settings: [X] Save options on exiting AntiVir Priority: medium Drives: A: Floppy drive C: Hard disk D: CD-ROM E: CD-ROM Start of scan: lundi 15 août 2005 23:22 Memory test OK Master boot record of hard disk HD0 OK Boot record of drive C: OK C:\ pagefile.sys Access denied! Error during file opening! This is a Windows swap file. This file is locked by Windows. Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\Angelique NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\Angelique\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\LocalService NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\NetworkService NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Angelique\Data chandir.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! chandir.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! chn.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! chn.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! D0000000.FCS Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! L0000001.FCS Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_die.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_die.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_dnd.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_dnd.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_ext.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_ext.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_rcv.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_rcv.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! storydb.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! storydb.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Program Files\Yahoo!\YPSR\Quarantine 20050813214853.zip ArchiveType: ZIP NOTE! The whole archive is password protected 20050814231807.zip ArchiveType: ZIP NOTE! The whole archive is password protected Error! Could not change directory: System Volume Information C:\WINDOWS\system32\config default Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! default.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SAM Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SAM.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SECURITY Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SECURITY.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! software Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! software.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! system Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! system.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\WINDOWS\Temp CS39C1.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C10.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C11.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C12.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C13.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C14.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C15.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C16.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C17.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C18.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C19.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C1A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C1B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C1C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C1D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C1E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C1F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C20.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C21.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C22.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C23.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C24.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C25.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C26.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C27.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C28.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C29.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C2F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C30.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C31.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C32.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C33.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C34.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C35.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C36.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C37.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C38.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C39.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C3F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C40.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C41.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C42.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C43.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C44.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C45.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C46.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C47.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C48.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C49.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C4F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C50.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C51.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C52.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C53.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C54.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C55.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C56.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C57.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C58.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C59.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C5F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C6.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C60.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C61.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C62.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C63.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C64.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C65.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C7.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C8.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39C9.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39CA.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39CB.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39CC.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39CD.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39CE.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS39CF.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! End of scan: lundi 15 août 2005 23:35 Time taken: 12:50 min 1552 directories were scanned 59660 files were scanned 142 warning messages were issued 0 files were deleted 0 files were repaired 0 detections -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
Y'a plus personne Sniff bises merci charles -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
Me revoilà Et j'ai tout fait en mode sans échec. 1) le rapport Hijackthis Logfile of HijackThis v1.99.1 Scan saved at 22:49:55, on 15/08/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\LVComsX.exe C:\Documents and Settings\Angelique\Mes documents\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll" O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [OpiStat] C:\Program Files\OpiStat\OpiStat\OpiStat.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Program Files\OpenOffice.org1.1.4\program\quickstart.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {B3231E01-D1EA-4BF1-B872-CF21619704F3} (NMInstall Control) - http://a14.g.akamai.net/f/14/7141/144000s/...ANEL_EUROPE.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game16.zylomgames.com/activex/zylomgamesplayer.cab O18 - Protocol: bw+0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: ET dll Locator (frepdll.exe) - Unknown owner - C:\WINDOWS\frepdll.exe (file missing) O23 - Service: hexadecimal (HexadecimaRepresentation) - Unknown owner - C:\WINDOWS\Edit.exe (file missing) O23 - Service: msecure (mcsecure) - Unknown owner - C:\WINDOWS\mcsecure.exe O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe bon voilà et je n'es pas enlevé antivir. A vous les expère merci bisous -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
Alors pour répondre à vous deux non je ne l'ai pas fait en mode ss échec je vais le faire de suite pardon et pour norman je les desactivé pour antivir voilà donc je vous dis à tout à l'heure si vous êtes encore là bise. -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
Me revoilà donc voici le rapport d'anti vir mais pas en mode sans échec!! Merci!! Creation date of the report file: lundi 15 août 2005 21:56 AntiVir®/XP (2000 + NT) PersonalEdition Classic Build 1047 vom 07.06.2005 Mainprogram 6.31.00.03 of 10.05.2005 VDF file 6.31.1.117 (0) of 15.08.2005 This program is for PERSONAL USE only. Any other use is PROHIBITED. Informations regarding commercial versions of AntiVir may be obtained from: www.hbedv.com. Scanning for 201577 virus strains and unwanted programs. Licensed for: AntiVir Personal Edition Serial number: 0000149996-WURGE-0001 Please enter the workstation and contact name with phone number in this form: Name ___________________________________________ Street ___________________________________________ Town ___________________________________________ Phone/Fax ___________________________________________ Email ___________________________________________ Platform: Windows NT Workstation Windows version: 5.1 Build 2600 () Username: Angelique Processor: Pentium Working memory: 196080 KB free Version information: AVWIN.DLL : 6.31.00.03 561192 10.05.2005 16:50:16 AVEWIN32.DLL : 6.31.1.0 823808 19.07.2005 17:54:12 AVGNT.EXE : 6.31.00.01 168039 10.05.2005 16:50:16 AVGUARD.EXE : 6.31.00.01 238120 29.04.2005 08:07:12 GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 11:24:10 AVGCMSG.DLL : 6.31.00.00 295029 29.04.2005 08:07:16 AVGNTDW.SYS : 6.31.00.01 32896 29.04.2005 08:07:16 AVPACK32.DLL : 6.31.00.03 323664 25.05.2005 10:43:02 AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 18:10:20 AVWIN.DLL : 6.31.00.03 561192 10.05.2005 16:50:16 AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 18:10:22 AVSched32.EXE : 6.30.00.00 110632 01.02.2005 11:24:10 AVSched32.DLL : 6.30.00.00 122880 01.02.2005 11:24:10 AVREG.DLL : 6.30.00.03 41000 10.02.2005 18:47:48 AVRep.DLL : 6.31.01.110 1282088 15.08.2005 07:48:40 INETUPD.EXE : 6.31.00.02 249915 29.04.2005 08:07:14 INETUPD.DLL : 6.31.00.02 143360 29.04.2005 08:07:14 CTL3D32.DLL : 2.31.000 27136 28.08.2001 14:00:00 MFC42.DLL : 6.00.8665.0 995383 28.08.2001 14:00:00 MSVCRT.DLL : 7.0.2600.0 (xpclient.010817-1148 MSVCRT.DLL : 7.0.2600.0 (xp 322560 28.08.2001 14:00:00 CTL3DV2.DLL : No information Configuration file: Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG Start path: C:\Program Files\AVPersonal Command line: Start mode: unknown Mode of report file: [ ] Do not create report [X] Overwrite report [ ] Append new report Data in report file: [X] Infected files [ ] Infected files with paths [ ] All scanned files [ ] Full information Abridge report file: [ ] Abridge report file Warnings in report: [X] Access denied/file locked [X] Wrong file size in directory [X] Wrong creation time in directory [ ] COM file is too large [X] Invalid start address [X] Invalid EXE header [X] Possibly damaged Summary report: [X] Create summary report Output file: AVWIN.ACT Maximum number of entries: 100 Where to search: [X] Memory [X] Boot record of selected drives [ ] Report unknown boot sectors [X] All files [ ] Program files Response in case of a detection: [X] Repair with prompt [ ] Repair without prompt [ ] Delete with prompt [ ] Delete without prompt [ ] Write in report file only [X] Acoustic alarm Response in case of destroyed files: [X] Delete with prompt [ ] Delete without prompt [ ] Ignore Response in case of destroyed files: [X] No change [ ] Current system time [ ] Correct date Drag&drop settings: [X] Scan subdirectories Profile settings: [X] Scan subdirectories Archive options [X] Search archive [X] Archive types to leave out 1002 1001 1000 Miscellaneous options: Temporary path: %TEMP% -> C:\Program Files\AVPersonal\BUILD.DAT [X] Overwrite infected files [ ] Detect idle time [X] Allow interruptions of scan [X] Load AVWin®/NT Guard on System start General settings: [X] Save options on exiting AntiVir Priority: medium Drives: A: Floppy drive C: Hard disk D: CD-ROM E: CD-ROM Start of scan: lundi 15 août 2005 21:56 Memory test OK Master boot record of hard disk HD0 OK Boot record of drive C: OK C:\ pagefile.sys Access denied! Error during file opening! This is a Windows swap file. This file is locked by Windows. Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\Angelique NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\Angelique\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\LocalService NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\NetworkService NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Angelique\Data chandir.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! chandir.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! chn.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! chn.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! D0000000.FCS Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! L0000001.FCS Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_die.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_die.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_dnd.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_dnd.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_ext.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_ext.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_rcv.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! prs_rcv.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! storydb.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! storydb.idx Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Program Files\Yahoo!\YPSR\Quarantine 20050813214853.zip ArchiveType: ZIP NOTE! The whole archive is password protected 20050814231807.zip ArchiveType: ZIP NOTE! The whole archive is password protected Error! Could not change directory: System Volume Information C:\WINDOWS update-sp3.html [DETECTION] Contains signature of the HTML script virus HTML/MediaTicke.A.1 WAS DELETED! VPN.exe [DETECTION] Contains signature of the worm WORM/SdBot.aad.2.1 WAS DELETED! C:\WINDOWS\system32 mondrv.sys [DETECTION] Is the Trojan horse TR/Rootkit.M WAS DELETED! C:\WINDOWS\system32\config default Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! default.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SAM Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SAM.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SECURITY Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SECURITY.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! software Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! software.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! system Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! system.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\WINDOWS\Temp CS37C1.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C10.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C11.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C12.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C13.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C14.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C15.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C16.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C17.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C18.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C19.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C1A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C1B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C1C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C1D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C1E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C1F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C20.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C21.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C22.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C23.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C24.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C25.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C26.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C27.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C28.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C29.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C2F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C30.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C31.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C32.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C33.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C34.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C35.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C36.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C37.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C38.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C39.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C3F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C40.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C41.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C42.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C43.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C44.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C45.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C46.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C47.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C48.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C49.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C4F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C50.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C51.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C52.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C53.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C54.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C55.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C56.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C57.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C58.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C59.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5A.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5B.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5C.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5D.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5E.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C5F.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C6.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C60.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C61.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C62.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C63.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C64.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C65.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C7.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C8.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37C9.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37CA.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37CB.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37CC.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37CD.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37CE.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! CS37CF.tmp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! End of scan: lundi 15 août 2005 22:10 Time taken: 14:00 min 1549 directories were scanned 60331 files were scanned 142 warning messages were issued 3 files were deleted 0 files were repaired 3 detections -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
salut escuse moi je t'es pas remercier j'ai vu ton message qu'après avoir posté mon truc en charabia merci beaucoup j'espère que je serai pas rop nule. bisous à tous -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a répondu à un(e) sujet de ange1402 dans Analyses et éradication malwares
Logfile of HijackThis v1.99.1 Scan saved at 21:38:19, on 15/08/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\Norman\Bin\ZLH.EXE C:\Program Files\OpiStat\OpiStat\OpiStat.exe C:\WINDOWS\System32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\OpenOffice.org1.1.4\program\soffice.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\mcsecure.exe C:\Norman\Bin\Zanda.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\nipsvc.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Angelique\Mes documents\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll" O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [OpiStat] C:\Program Files\OpiStat\OpiStat\OpiStat.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Program Files\OpenOffice.org1.1.4\program\quickstart.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {B3231E01-D1EA-4BF1-B872-CF21619704F3} (NMInstall Control) - http://a14.g.akamai.net/f/14/7141/144000s/...ANEL_EUROPE.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game16.zylomgames.com/activex/zylomgamesplayer.cab O18 - Protocol: bw+0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {24B8F777-0A18-400F-A1F1-D42F8637B36D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: ET dll Locator (frepdll.exe) - Unknown owner - C:\WINDOWS\frepdll.exe (file missing) O23 - Service: hexadecimal (HexadecimaRepresentation) - Unknown owner - C:\WINDOWS\Edit.exe (file missing) O23 - Service: msecure (mcsecure) - Unknown owner - C:\WINDOWS\mcsecure.exe O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe Voilà alors ça pour moi c'est du charabia et je suis actuellement en train de scaner avec antivir et franchement je vous remercie énormément merci megataupe -
[Résolu] Mon PC est plein de virus et de trojan
ange1402 a posté un sujet dans Analyses et éradication malwares
Bonjour à tous , dans toutes mes recherches en générales je tombe souvent sur Zébulon qui je dois dire ma souvent dépanée donc j'ai décidé aujourd'hui de m'inscrire je ne suis pas très forte en informatique et je suis désolée au cas ou le sujet ne serai pas à sa place mille pardon. Bon voilà ce qui m'ammène. J'ai beaucoup de virus et j'ai réussis à en illiminé pas mal grace au scaner en ligne de KASPERKY qui je dois dire m'a vachement suprise en s'achant que mon anti virus norman ne m'avait évidament pas trouver les 15 virus et chevaux de Troie qui trainent sur mon disque dur. et maintenant il ne m'en reste que quelqu'uns mais cela j'arrive pas à les enlever et parfois je ne les trouves même pas sur mon DD Enfin tous ça pour dire que j'en ai encore et j'ai beau les supprimer en mode sans échec (après avoir désactivé la restauration , tous vider les fichiers temporaire et mis les fichiers caché en vus et refait un scan ect..) le seul truc que je ne sais pas faire c'est le logiciel hytachy je crois je sais même pas si cela s'écris comme ça En plus je suprime les fichiers sans savoir si il y a un risque en faite, car j'ai eu aussi le message suivant après avoir suprimer certain C: e45gd3.ex le processeur NTVDM CS i06b4 avec un IP et le truc est sous dos en 16 bit Donc je peux donner que le rapport de kasperky: KASPERSKY ON-LINE SCANNER REPORT Monday, August 15, 2005 20:59:36 Operating System: Microsoft Windows XP Professional, (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 15/08/2005 Kaspersky Anti-Virus database records: 135330 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - Folders: C:\ Scan Statistics: Total number of scanned objects: 25218 Number of viruses found: 2 Number of infected objects: 5 Number of suspicious objects: 0 Duration of the scan process: 947 sec Infected Object Name - Virus Name C:\WINDOWS\frepdll.exe Infected: Backdoor.Win32.SdBot.aad C:\WINDOWS\mcsecure.exe Infected: Backdoor.Win32.SdBot.aad C:\WINDOWS\system32\hpdriver.sys Infected: Rootkit.Win32.Agent.ae C:\WINDOWS\system32\mondrv.sys Infected: Rootkit.Win32.Agent.ae C:\WINDOWS\VPN.exe Infected: Backdoor.Win32.SdBot.aad Scan process completed. J'ai beau chercher mais je tombe souvant sur des sites en anglais et l'anglais et moi ça fait deux. Je ne trouve pas de sujet sur comment suprimer c'est trucs et aussi les suprimer sans qu'ils reviennent quand ils sont en quarentaine. Alors sinon mon pc à internet explorer 6 et je suis cablé et donc internet en permanance. et je suis en 1024. j'ai XP , par contre si vous voulez plus de détails dites moi ou je peux les chercher et je le ferai. ben voilà je crois que j'en ai assez dit pour l'instant dans l'attente de vous lire je vous remercie beaucoup beaucoup.