Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés


Alors voilà déjà le rapport d'Antivir, après que j'ai effectué les opérations concernant Emule, Kazaa et Azerus :




Avira AntiVir Personal
Report file date: mardi 5 août 2008  17:23

Scanning for 1536287 virus strains and unwanted programs.

Licensed to:	  Avira AntiVir PersonalEdition Classic
Serial number:	0000149996-ADJIE-0001
Platform:		 Windows XP
Windows version:  (Service Pack 2)  [5.1.2600]
Boot mode:		Normally booted
Username:		 Alundra
Computer name:	CENTERPERK

Version information:
BUILD.DAT	 :	  16933 Bytes  11/07/2008 12:57:00
AVSCAN.EXE	:	   315649 Bytes  26/06/2008 09:57:53
AVSCAN.DLL	:		40705 Bytes  26/05/2008 08:56:40
LUKE.DLL	  :	   164097 Bytes  12/06/2008 13:44:19
LUKERES.DLL   :		12033 Bytes  26/05/2008 08:58:52
ANTIVIR0.VDF  :	11030528 Bytes  18/07/2007 11:33:34
ANTIVIR1.VDF  :	  8182784 Bytes  24/06/2008 14:54:15
ANTIVIR2.VDF  :	2316800 Bytes  04/08/2008 16:18:05
ANTIVIR3.VDF  :	  75264 Bytes  05/08/2008 16:18:06
Engineversion :  
AEVDF.DLL	 :	   102772 Bytes  09/07/2008 09:46:50
AESCRIPT.DLL  :	  311675 Bytes  05/08/2008 16:18:17
AESCN.DLL	 :	  119156 Bytes  05/08/2008 16:18:16
AERDL.DLL	 :	  418165 Bytes  09/07/2008 09:46:50
AEPACK.DLL	:	   364917 Bytes  05/08/2008 16:18:15
AEOFFICE.DLL  :	  192891 Bytes  05/08/2008 16:18:13
AEHEUR.DLL	:	 1343863 Bytes  05/08/2008 16:18:12
AEHELP.DLL	:	  115063 Bytes  09/07/2008 09:46:50
AEGEN.DLL	 :	  315765 Bytes  05/08/2008 16:18:09
AEEMU.DLL	 :	   430452 Bytes  05/08/2008 16:18:08
AECORE.DLL	:	   172406 Bytes  05/08/2008 16:18:07
AEBB.DLL	  :		53617 Bytes  24/04/2008 09:50:42
AVWINLL.DLL   :	   15105 Bytes  09/07/2008 09:40:05
AVPREF.DLL	:		38657 Bytes  16/05/2008 10:28:01
AVREP.DLL	 :		98344 Bytes  05/08/2008 16:18:06
AVREG.DLL	 :		33537 Bytes  09/05/2008 12:26:40
AVARKT.DLL	:	  307457 Bytes  12/02/2008 09:29:23
AVEVTLOG.DLL  :	  119041 Bytes  12/06/2008 13:27:49
SQLITE3.DLL   :	  339968 Bytes  22/01/2008 18:28:02
SMTPLIB.DLL   :	   28929 Bytes  12/06/2008 13:49:40
NETNT.DLL	 :		 7937 Bytes  25/01/2008 13:05:10
RCIMAGE.DLL   :	 2371841 Bytes  12/06/2008 14:48:07
RCTEXT.DLL	:	   86273 Bytes  27/06/2008 14:34:37

Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:, E:, 
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: mardi 5 août 2008  17:23

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'AcroRd32.exe' - '1' Module(s) have been scanned
Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
Scan process 'kg0g1i0n.exe' - '1' Module(s) have been scanned
Scan process 'RegCleanr.exe' - '1' Module(s) have been scanned
Scan process 'RegCleanr.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
28 processes with 28 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO]	  No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO]	  No virus was found!

Starting to scan the registry.
The registry was scanned ( '42' files ).

Starting the file scan:

Begin scan in 'C:\' <QG>
[WARNING]   The file could not be opened!
[WARNING]   The file could not be opened!
C:\Deckard\System Scanner\backup\DOCUME~1\ALUNDR~1.CEN\LOCALS~1\Temp\0v4fy5x7.exe
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE]	  The file was deleted!
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\
[DETECTION] Contains suspicious code GEN/PwdZIP
[NOTE]	  The detection was classified as suspicious.
[NOTE]	  The file was moved to '490c80cd.qua'!
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\
[DETECTION] Contains suspicious code GEN/PwdZIP
[NOTE]	  The detection was classified as suspicious.
[NOTE]	  The file was moved to '490b80d7.qua'!
C:\Documents and Settings\Alundra.CENTERPARK\.housecall6.6\Quarantine\antispy.exe.bac_a02992
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Alundra.CENTERPARK\.housecall6.6\Quarantine\antispy.exe.bac_a02992
  [DETECTION] Is the TR/Click.Agent.EN Trojan
[NOTE]	  The file was deleted!
C:\Documents and Settings\Alundra.CENTERPARK\.housecall6.6\Quarantine\InstaFinderK_inst.exe.bac_a02992
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Alundra.CENTERPARK\.housecall6.6\Quarantine\InstaFinderK_inst.exe.bac_a02992
  [DETECTION] Contains recognition pattern of the DR/Toolbar.404Search.H dropper
[NOTE]	  The file was deleted!
C:\Documents and Settings\LocalService\Local Settings\Temp\Hv6So1h6.exe
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE]	  The file was deleted!
C:\Program Files\Bodom-Child - RaBBi\RGSS\Standard\Graphics.exe
[0] Archive type: CAB SFX (self extracting)
--> Graphics\Animations\002-Action02.png
  [WARNING]   No further files can be extracted from this archive. The archive will be closed
[WARNING]   No further files can be extracted from this archive. The archive will be closed
[WARNING]   The file could not be opened!
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[WARNING]   The file could not be deleted!
[NOTE]	  Attempting to perform action using the ARK lib.
[NOTE]	  The file was deleted!
Begin scan in 'D:\'
Search path D:\ could not be opened!
System error [21]: Le périphérique n'est pas prêt.
Begin scan in 'E:\'
Search path E:\ could not be opened!
System error [21]: Le périphérique n'est pas prêt.

End of the scan: mardi 5 août 2008  19:13
Used time:  1:50:14 Hour(s)

The scan has been done completely.

  8700 Scanning directories
573085 Files were scanned
  5 viruses and/or unwanted programs were found
  2 Files were classified as suspicious:
  5 files were deleted
  0 files were repaired
  2 files were moved to quarantine
  0 files were renamed
  4 Files cannot be scanned
573074 Files not concerned
  5535 Archives were scanned
  6 Warnings
  7 Notes


Et le nouveau rapport DSS :


Deckard's System Scanner v20071014.68
Run by Alundra on 2008-08-05 20:36:49
Computer is in Normal Mode.

-- HijackThis (run as Alundra.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:37:14, on 05/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\RegCleaner\RegCleanr.exe
C:\Program Files\RegCleaner\RegCleanr.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Alundra.CENTERPARK\Bureau\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) -
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) -
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

End of file - 6127 bytes

-- Files created between 2008-07-05 and 2008-08-05 -----------------------------

2008-08-05 17:16:52		 0 d-------- C:\Program Files\Avira
2008-08-05 17:16:52		 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-05 16:11:10		 0 d-------- C:\Program Files\TengScribe
2008-08-05 11:55:43		 0 d-------- C:\Program Files\RegCleaner
2008-08-05 11:05:00		 0 d-------- C:\WINDOWS\BDOSCAN8
2008-08-04 22:21:10		 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-04 22:15:17		 0 dr-h----- C:\Documents and Settings\Alundra.CENTERPARK\Recent
2008-08-04 21:38:25		 0 d-------- C:\Program Files\CCleaner
2008-07-18 01:21:27		 0 d-------- C:\Documents and Settings\Alundra.CENTERPARK\.housecall6.6
2008-07-17 21:02:46		 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Help
2008-07-17 11:16:56		 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-07-17 11:00:35		 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Macromedia
2008-07-17 11:00:24		 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Adobe
2008-07-17 11:00:12		 0 dr------- C:\Documents and Settings\NetworkService\Favoris

-- Find3M Report ---------------------------------------------------------------

2008-08-05 12:01:44	 11383 --a------ C:\WINDOWS\system32\nvModes.dat
2008-08-05 11:30:08		 0 d-------- C:\Program Files\Ripp-it_AM
2008-08-05 10:56:38		 0 d-------- C:\Program Files\Fichiers communs
2008-08-05 10:54:00		 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-05 10:07:49		 0 d-------- C:\Program Files\Java
2008-08-05 10:01:03		 0 d-------- C:\Program Files\AdVantage
2008-07-17 03:55:11		 0 d-------- C:\Documents and Settings\Alundra.CENTERPARK\Application Data\Adobe
2008-07-05 19:43:29		 0 d-------- C:\Documents and Settings\Alundra.CENTERPARK\Application Data\OpenOffice.org2
2008-06-26 19:27:27		 0 d-------- C:\Program Files\EasyPHP1-7
2008-06-12 23:53:51		 0 d-------- C:\Documents and Settings\Alundra.CENTERPARK\Application Data\DAEMON Tools

-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown

"@"="" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [12/06/2008 14:28]

*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB
*Newly Created Service* - SSMDRV

-- End of Deckard's System Scanner: finished at 2008-08-05 20:37:36 ------------


En te remerciant encore et toujours !


• supprime:


C:\Documents and Settings\Alundra.CENTERPARK\.housecall6.6




• vide la quarantaine de spybot


• Finir nettoyage:


» telecharge sur ton bureau:


- AtfCleaner -->


ATF Cleaner

Double-clique ATF-Cleaner.exe afin de lancer le programme.

Sous l'onglet Main, choisis : Select All

Clique sur le bouton Empty Selected, patiente le temp du nettoyage, ok

Si tu utilises le navigateur Firefox :

Clique Firefox au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Si tu utilises le navigateur Opera :

Clique Opera au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Clique Exit, du menu prinicipal, afin de fermer le programme.


»desactiver puis réactiver la restauration systeme de cette maniere:


Tu as toujours le meme soucis????

Posté(e) (modifié)



Tout ce que je peux dire au sujet du problème, c'est qu'apparemment, le programme "iexplore.exe" ne se lance plus.

Pour la première fois, je ne le vois plus dans la liste des processus.

Si c'est définitif, je ne peux que te remercier du fond du cœur, sincèrement, pour tout le temps que tu m'as accordé.

En plus de tout, j'ai bénéficier d'un nettoyage en règle, merci 1000 fois, vraiment.


Est ce que je dois faire autre chose, publier un autre rapport ?

Est ce que je peux desinstaller/effacer TOUS les petits logiciels que j'ai installé ? Est ce que je dois en garder certains ?

Modifié par Malta

Merci 1000 fois encore...


Dernière petite chose :


Est ce que je peux desinstaller/effacer TOUS les petits logiciels que j'ai installé ? Est ce que je dois en garder certains ?



Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...