Infecté par Win32:Trojan-gen. {UPX!}

Fermé
gaetan - 2 avril 2007 à 11:41
 Blax - 17 avril 2007 à 15:33
bonjour , j'ai un problème, a chaque démarrage avast me trouve ce virus Win32:Trojan-gen. {UPX!} même après un scan. aidez moi svp . merci
A voir également:

44 réponses

ah aussi je voulais signaler que lorsque je lance une installation du type setup mon pc redémarre et impossible de faire l'installation
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
5 avril 2007 à 14:40
ok smitfraud n'a rien detecté donc tu peu le supprimer

telecharge gmer :

https://www.majorgeeks.com/files/details/gmer.html
ouvre gmer coches files / registery /services/ devices

ensuite colle le raport ici

a+++
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
5 avril 2007 à 16:45
tu t'en sort?

a+++
0
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-05 23:43:50
Windows 5.1.2600 Service Pack 1


---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 823DA1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 823DA1D8
Device \Driver\00000054 \Device\00000043 IRP_MJ_POWER [F844DD74] sptd.sys
Device \Driver\00000054 \Device\00000043 IRP_MJ_SYSTEM_CONTROL [F84672A2] sptd.sys
Device \Driver\00000054 \Device\00000043 IRP_MJ_PNP [F8468228] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 821D31D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{CCDD9CDA-513B-48B2-B23D-55013D533206} IRP_MJ_CREATE 81FDF980
Device \Driver\NetBT \Device\NetBT_Tcpip_{CCDD9CDA-513B-48B2-B23D-55013D533206} IRP_MJ_CLOSE 81FDF980
Device \Driver\NetBT \Device\NetBT_Tcpip_{CCDD9CDA-513B-48B2-B23D-55013D533206} IRP_MJ_DEVICE_CONTROL 81FDF980
Device \Driver\NetBT \Device\NetBT_Tcpip_{CCDD9CDA-513B-48B2-B23D-55013D533206} IRP_MJ_INTERNAL_DEVICE_CONTROL 81FDF980
Device \Driver\NetBT \Device\NetBT_Tcpip_{CCDD9CDA-513B-48B2-B23D-55013D533206} IRP_MJ_CLEANUP 81FDF980
Device \Driver\NetBT \Device\NetBT_Tcpip_{CCDD9CDA-513B-48B2-B23D-55013D533206} IRP_MJ_PNP 81FDF980
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 8236F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 8236F1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 821D31D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 821A61D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 821A61D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 821A61D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 821A61D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 821A61D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 821A61D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 821A61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 823DC1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 823DC1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 821F3980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 821F3980
Device \Driver\poof \Device\poofpoof IRP_MJ_CREATE F891E6D0
Device \Driver\poof \Device\poofpoof IRP_MJ_CLOSE F891E6D0
Device \Driver\poof \Device\poofpoof IRP_MJ_DEVICE_CONTROL F891E5C8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 821F3980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 821F3980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 81FDF980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 81FDF980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 81FDF980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 81FDF980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 81FDF980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 81FDF980
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 81FDF980
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 81FDF980
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 81FDF980
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 81FDF980
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 81FDF980
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 81FDF980
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 821D31D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 81FD7980
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 821D31D8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 81FD7980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 81FD7980
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 821D31D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 821D31D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 821D31D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 821D31D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CREATE 821A61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CLOSE 821A61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 821A61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 821A61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_POWER 821A61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 821A61D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_PNP 821A61D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 823DC1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 823DC1D8
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_CREATE 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_CLOSE 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_POWER 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1Port2Path0Target0Lun0 IRP_MJ_PNP 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_CREATE 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_CLOSE 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_DEVICE_CONTROL 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_POWER 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_SYSTEM_CONTROL 8219A980
Device \Driver\a5xngwvw \Device\Scsi\a5xngwvw1 IRP_MJ_PNP 8219A980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 820D5870
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 820D5870
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 00:20
bonsoir tu as coché device seulement?

peu tu refaire le scan et coché files / registery /services/


a++++
0
non j'ai coché ce que tu m'a dit aussi. je suis en train de refaire un scan sans device.
0
j'ai fait le scan mais rien du tout n'est signaler et sa se bloque lors de registery au fichier lavasoft-adaware se personal
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 12:57
bonjour tu peu supprimer gmer et telecharge ceci

telecharge the killbox

http://www.downloads.subratam.org/KillBox.exe


1.redemarre en mode sans echec (redemarage + tapotte sans arret sur F8 desque l'ordi s'allume)


2.Double clic sur killbox.exe (Pocket Killbox)

- Dans "Full Path of File to Delete"
copie et colle:

C:\WINDOWS\System32\totour.exe

-clique sur single file
- clique sur la croix rouge
- une fenêtre va apparaître pour confirmation de suppression clique sur YES

tu fait pareil avec ce fichier :

c:\cp1041.nls



4.ensuite va dans post de travail / lecteur C: cherche et supprime le dossier nommée : !KillBox

ce dossier contien tout les virus supprimé avec the kill box

5.vide la corbeille

6. lance ccleaner


redemare en mode normal et dit moi ce que ca donne

a++
0
je suis arrivé a supprimer c:\cp1041.nls mais lorsque j'ai voulu supprimer C:\WINDOWS\System32\totour.exe un message ma indiquer qu'il ne me l'a pas trouvé. lorsque j'ai redémarré avast me l'a toujours rapporter
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 14:15
ok on va essayé avec un autre programe


telecharge OTMoveIt by OldTimer sur ton bureau

http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

double click sur OTMoveIt.exe

copie et colle dans le paneau "Paste List of Files/Folders to be moved":


C:\cp1041.nls


Click sure bouton Moveit!


si il n'arrive pas a supprimer le fichier il va te demandé de demarrer l'ordi pour le supprimer ; click sur yes pour accepter le redemarrage

a++++
0
voila j'ai fait ce que tu ma dis, ot move it a supprimer le fichier. j'ai redémarré pour voir si le virus était toujours présent mais il l'est toujours.
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 15:15
il est corriace mais on va y'arrivé :p


analyse stp ce fichier

Rend toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clik sur parcourir
Recherche ceci :

C:\WINDOWS\system32\drivers\ndis.sys

click sur send , attend quelque instant ensuite colle le resultat ici

a+++
0
ca n'a pas marché, j'ai seulement eu:
0 bytes size received / Se ha recibido un archivo vacio
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 18:40
bonjour je pense que c kerio qui bloque l'analyse desactive ensuite recommence

Rend toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html

dans le champ de recherche copie/colle

C:\WINDOWS\system32\drivers\ndis.sys

click sur send , attend quelque instant ensuite colle le resultat ici

a+++
0
c'est toujours pareil j'ai le même message
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 19:24
ok je vais te preparer une manip je revien d'ici peu


a++++
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
6 avril 2007 à 20:03
ok en fait le virus utilise ce fichier windows ( ndis.sys
) pour se regenerer , il faut maintenant replacé ce fichier system verolé par l'original pour cela il te faudera le cd windows xp


tout d'abord telecharge super antispyware pour le moment c'est le seul qui traite bien cette infection

https://www.malekal.com/tutoriel-et-guide-superantispyware/


1.redemare en mode sans echec (redemarrage + tapotte sans arret sur la touche F8 desque l'ordi s'allume)

2. affiche les extention windows comme ceci :


clicker sur demarrer/panneau de configuration/option des dossiers/affichage

decoche : "masquer les extention dont le type est connu"

Puis fais «appliquer» pour valider les changements.


3.met le cd windows xp ensuite va dans post de travail / click droit sur le lecteur qui contien le cd windows et choisi rechercher

dans le champ de rechreche : tape ndis

il va te trouver ce fichier : NDIS.SY_ . copie le fichier et colle le dans le bureau et renome le en : ndis.sys ensuite met le dans le dossier en gras : C:\WINDOWS\system32\drivers\

il va te dire que ce fichier existe deja , choisi remplacé


ensuite lance super antispyware que t'as telecharger et suis les indication du tutorial

a+++

bon courage
0
j'ai fait ce que tu m'as demandé mais lorsque j'ai redémarrer mon pc je me retrouve sans internet, jei regardé un peu, sur ma carte réseau tous les composant son avec un point d'exclamation jaune, et dise que windows ne peut pas charger le pilote car il est soit endommager soit absent. que dois-je faire?
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 625
7 avril 2007 à 13:05
bonjour essay de reparer la connexion avec ce programe

telecharge le a partir d'un autre ordi puis transfer le sur ton ordi a l'aide d'une clée usb

http://babin.nelly.free.fr/WinsockFix.zip

decompress le pour cela click droit sur WinsockFix.zip et choisi extraire ici

ensuite double click WinsockFix.exe puis choisi fix

redemare le pc et dit moi ce que ca donne

a++++
0
j'ai fait WinsockFix.exe avec fix ensuite l'ordi a redémarré mais c'est pareil qu'avant.
0