finalement, j'ai trouvé le log de OTMovelt
Oui, ton antivirus (le parapluie rouge).
par contre, je dois scanner quoi ? Local Drives ou Local Hard Disks ? ou alors tous les trucs que j'ai ?
Local Hard Disks ---> Ton ou tes disque(s) dur(s).
ok, ça risque d'être un peu long xD
Je m'en doute.
AntiVir PersonalEdition Classic
Report file date: mardi 26 août 2008 22:10
Jobname: 'Local Hard Disks'
Scanning for 370940 virus strains and unwanted programs.
Licensed to: AntiVir PersonalEdition Classic
Serial number: 0000149996-WURGE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Username: mattia
Computer name: PCMATTIA
Version informations:
AVSCAN.EXE : 7.0.0.35 540712 21/04/2006 13:47:04
AVSCAN.DLL : 7.0.0.34 41000 05/04/2006 12:03:57
LUKE.DLL : 7.0.0.34 114728 05/04/2006 12:03:58
LUKERES.DLL : 7.0.0.34 25640 05/04/2006 12:03:58
ANTIVIR0.VDF : 6.32.0.60 4323840 02/05/2006 09:29:08
ANTIVIR1.VDF : 6.34.0.209 1930240 02/05/2006 09:29:09
ANTIVIR2.VDF : 6.34.1.1 89600 01/05/2006 18:17:55
ANTIVIR3.VDF : 6.34.1.26 48128 01/05/2006 18:17:55
AVEWIN32.DLL : 7.0.0.8 1171968 21/04/2006 16:40:14
AVPREF.DLL : 6.34.0.0 38440 18/01/2006 13:06:00
AVREP.DLL : 6.34.1.20 2371624 01/05/2006 18:17:56
AVPACK32.DLL : 7.0.0.4 335912 29/03/2006 10:44:25
AVREG.DLL : 6.31.0.90 27688 28/07/2005 11:06:36
NETNT.DLL : 6.32.0.0 6696 27/09/2005 08:56:49
NETNW.DLL : 6.32.0.0 9768 27/09/2005 08:56:49
Start of the scan: mardi 26 août 2008 22:10
Start scanning boot sectors:
Boot sector 'H:'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( 19 files ).
Starting the file scan:
H:\pagefile.sys
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\0f43c7a06ae5
bf90f9ea1d5678bc5ab6_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\45173ece70b6
617b600df9fed3bccffc_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\4d04c92ffc17
e392b2f8185301b2657a_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\50ac0d8df04f
0bd8a840d61c3789ec60_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\5f85f7bad76e
6d89bc242b3f7b4a4b3c_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\83e49838d25f
65fbe8d8b1bbf2a21b78_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\9283374c187b
f7da549213b320185a53_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\ee5d1eefde6d
93c56ecb933be18d13c1_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\f0b53a3f0cb9
92c7b14f51b272a729fe_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\f1a637bc9e20
2437541348295e2d4263_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\ff93a1d9052b
7261398150171688797d_a2af102b-7ae7-4c3e-bb62-df63f
87f3c34
[WARNING] The file could not be opened!
H:\Documents and Settings\mattia\Local Settings\Temp\etilqs_EmlyRm2IeNFbodt3mBYm
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\default
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\software
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\system
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\atapi.sys
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\dtscsi.sys
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\sptd2957.sys
[WARNING] The file could not be opened!
End of the scan: mardi 26 août 2008 23:27
Used time: 1:16:28 min
The scan has been done completely.
10822 Scanning directories
300802 Files were scanned
0 viruses and/or unwanted programs was found
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
2325 Archives were scanned
22 Warnings
0 Notes
voilà donc le rapport de l'analyse antivir
bref, en tout cas, j'te remercie widemeo pour tout ce que t'as fait pour l'instant, mais là, je vais un peu arreter pour aujourd'hui ^^.
Donc peut-être à demain, pour peut-être poursuivre ma purification... xD
Merci encore
Ok.
re widemeo, si tu es là, ben n'hésite pas à me dire tout ce que tu sais, si ça t'ennuies pas trop, ou peut-être que tout ce que tu m'a conseillé de faire suffit, en tout cas, encore merci pour ton aide
up
Poste un nouveau rapport HijackThis.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:22:56, on 28/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Ahead\InCD\InCDsrv.exe
H:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\AntiVir PersonalEdition Classic\sched.exe
H:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
H:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
H:\Program Files\Bonjour\mDNSResponder.exe
H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\Explorer.EXE
H:\Program Files\ScanSoft\OmniPageSE\opware32.exe
H:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
H:\WINDOWS\system32\ctfmon.exe
h:\windows\system32\rnwnw64s.exe
H:\WINDOWS\system32\rcntttdl.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\amsn\bin\wish.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Documents and Settings\mattia\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer par NUMERICABLE
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Int
ernet Settings,ProxyOverride = microweb;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - H:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SiSUSBRG] H:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Omnipage] H:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [avgnt] "H:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] "H:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{00-00-00-00-DW}] H:\WINDOWS\system32\rownw64j.exe DWbrk03FF
O4 - HKLM\..\Run: [{00-00-00-04-DW}] h:\windows\system32\rnwnw64s.exe DWbrk03FF
O4 - HKLM\..\Run: [ExploreUpdSched] H:\WINDOWS\system32\rcntttdl.exe DWbrk03FF
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] H:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "H:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] H:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Startup: Deewoo.lnk = H:\WINDOWS\system32\rcntttdl.exe
O4 - Startup: DW_Start.lnk = H:\WINDOWS\system32\rnwnw64s.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Interrompre le filtre de la page Web - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Refuser ce site Web - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Autoriser ce site Web - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - H:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - H:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by127fd.bay127.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - H:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - H:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - H:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: PACK SECURITE (BackWeb Plug-in - 542802) - Unknown owner -
H:\PROGRA~1\PACKSE~1\backweb\542802\Program\SERVIC
~1.EXE (file missing)
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - H:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - H:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 9329 bytes
pour analyser ton rapport, va sur
http://hijackthis.de/
et copie le la ou c'est indiqué, tu verras c'est simple
ces 2 fichiers
h:\windows\system32\rnwnw64s.exe
H:\WINDOWS\system32\rcntttdl.exe
semblent suspects, je suis même quasiment sur qu'il s'agit de virus auto générés par le programme malveillant, vu qu'une recherche google de leurs noms ne donne absolument aucun résultat : va dans h:\windows\, fais un clic droit sur le dossier system32 et fais "analyse antivir"
tiens nous au courant du résultat
PS: met bien antivir a jour avant
as tu essayé avec AVG ?
AVG c'est quoi ?
AntiVir PersonalEdition Classic
Report file date: jeudi 28 août 2008 11:35
Jobname: 'ShlExt'
Scanning for 370940 virus strains and unwanted programs.
Licensed to: AntiVir PersonalEdition Classic
Serial number: 0000149996-WURGE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Username: mattia
Computer name: PCMATTIA
Version informations:
AVSCAN.EXE : 7.0.0.35 540712 21/04/2006 13:47:04
AVSCAN.DLL : 7.0.0.34 41000 05/04/2006 12:03:57
LUKE.DLL : 7.0.0.34 114728 05/04/2006 12:03:58
LUKERES.DLL : 7.0.0.34 25640 05/04/2006 12:03:58
ANTIVIR0.VDF : 6.32.0.60 4323840 02/05/2006 09:29:08
ANTIVIR1.VDF : 6.34.0.209 1930240 02/05/2006 09:29:09
ANTIVIR2.VDF : 6.34.1.1 89600 01/05/2006 18:17:55
ANTIVIR3.VDF : 6.34.1.26 48128 01/05/2006 18:17:55
AVEWIN32.DLL : 7.0.0.8 1171968 21/04/2006 16:40:14
AVPREF.DLL : 6.34.0.0 38440 18/01/2006 13:06:00
AVREP.DLL : 6.34.1.20 2371624 01/05/2006 18:17:56
AVPACK32.DLL : 7.0.0.4 335912 29/03/2006 10:44:25
AVREG.DLL : 6.31.0.90 27688 28/07/2005 11:06:36
NETNT.DLL : 6.32.0.0 6696 27/09/2005 08:56:49
NETNW.DLL : 6.32.0.0 9768 27/09/2005 08:56:49
Start of the scan: jeudi 28 août 2008 11:35
Start scanning boot sectors:
Boot sector 'H:'
[NOTE] No virus was found!
Starting the file scan:
H:\WINDOWS\system32\config\default
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\software
[WARNING] The file could not be opened!
H:\WINDOWS\system32\config\system
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\atapi.sys
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\dtscsi.sys
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
H:\WINDOWS\system32\drivers\sptd2957.sys
[WARNING] The file could not be opened!
End of the scan: jeudi 28 août 2008 11:36
Used time: 01:30 min
The scan has been done completely.
193 Scanning directories
3986 Files were scanned
0 viruses and/or unwanted programs was found
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
2 Archives were scanned
9 Warnings
0 Notes
très bizarre
tu vas aller directement dans system32 et faire un clic droit>scan avec antivir sur les 2 fichiers dont je t'ai parlé
confirme moi que ton antivir est bien a jour.
AVG est un antivirus gratuit complémentaire, qui trouve certains trucs qu'antivir laisse passer, télécharge le ici, installe, met a jour et scanne
http://www.clubic.com/telecharger-fiche10997-avg-antivirus-free-edition.html
apparement, il y aurait un trojan horse generic11.ADC sur le
H:\WINDOWS\system32\rcntttdl.exe
d'après AVG
et voici le rapport avec Antivir sur le scan des 2 fichiers
AntiVir PersonalEdition Classic
Report file date: jeudi 28 août 2008 12:16
Jobname: 'ShlExt'
Scanning for 370940 virus strains and unwanted programs.
Licensed to: AntiVir PersonalEdition Classic
Serial number: 0000149996-WURGE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Username: mattia
Computer name: PCMATTIA
Version informations:
AVSCAN.EXE : 7.0.0.35 540712 21/04/2006 13:47:04
AVSCAN.DLL : 7.0.0.34 41000 05/04/2006 12:03:57
LUKE.DLL : 7.0.0.34 114728 05/04/2006 12:03:58
LUKERES.DLL : 7.0.0.34 25640 05/04/2006 12:03:58
ANTIVIR0.VDF : 6.32.0.60 4323840 02/05/2006 09:29:08
ANTIVIR1.VDF : 6.34.0.209 1930240 02/05/2006 09:29:09
ANTIVIR2.VDF : 6.34.1.1 89600 01/05/2006 18:17:55
ANTIVIR3.VDF : 6.34.1.26 48128 01/05/2006 18:17:55
AVEWIN32.DLL : 7.0.0.8 1171968 21/04/2006 16:40:14
AVPREF.DLL : 6.34.0.0 38440 18/01/2006 13:06:00
AVREP.DLL : 6.34.1.20 2371624 01/05/2006 18:17:56
AVPACK32.DLL : 7.0.0.4 335912 29/03/2006 10:44:25
AVREG.DLL : 6.31.0.90 27688 28/07/2005 11:06:36
NETNT.DLL : 6.32.0.0 6696 27/09/2005 08:56:49
NETNW.DLL : 6.32.0.0 9768 27/09/2005 08:56:49
Start of the scan: jeudi 28 août 2008 12:16
Start scanning boot sectors:
Boot sector 'H:'
[NOTE] No virus was found!
Starting the file scan:
H:\WINDOWS\system32\rcntttdl.exe
[WARNING] The file could not be opened!
End of the scan: jeudi 28 août 2008 12:16
Used time: 00:01 min
The scan has been done completely.
0 Scanning directories
2 Files were scanned
0 viruses and/or unwanted programs was found
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Archives were scanned
1 Warnings
0 Notes
Salut ! désolé de m'incruster mais j'aimerais que vous me disiez si mon log hijackthis est bon ?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:44, on 28/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Razer\Lachesis\razerhid.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Razer\Lachesis\OSD.exe
C:\Program Files\Razer\Lachesis\razertra.exe
C:\Program Files\Razer\Lachesis\razerofa.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers
communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.09\RivaTuner.exe" /S
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5784 bytes
Ps : dorian va sur msn stp
"AVG est un antivirus gratuit complémentaire"
donc aucun risque qu'il y est un conflit avec Antivir ?