Bonjour.
J'ai un ordinateur avec Windows xp 64 bits.
Depuis hier, quand j'ouvre une page internet, elle se ferme toute seule au bout d'un temps plus ou moins long.
Je travaille dans un établissement scolaire qui a pas mal de virus en ce moment.
J'ai suivi la procédure recommandée par mes collègues et je vous poste ceci :
############################## | UsbFix V 7.161 | [Recherche]
Utilisateur: roullier (Administrateur) # ROULLIER-PC
Mis à jour le 15/01/2014 par El Desaparecido - Team SosVirus
Lancé à 18:34:59 | 26/01/2014
Site Web :
http://www.usbfix.netChangelog :
http://www.usbfix.net/maj/Support :
http://www.sosvirus.net/Upload Malware :
http://www.sosvirus.net/upload_malware.phpContact :
http://www.usbfix.net/contact/PC: Packard Bell (WMCP78M)
CPU: AMD Athlon(tm) II X2 215 Processor
RAM -> [Total : 4095 Mo| Free : 2852 Mo]
Bios: AMI
Boot: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.16476
WB: Google Chrome : 32.0.1700.76
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
A:\ -> Disque amovible # 1 Mo (0 Mo libre(s) - 4%) [] # FAT
C:\ (%systemdrive%) -> Disque fixe # 688 Go (630 Go libre(s) - 92%) [Packard Bell] # NTFS
D:\ -> Disque fixe # 689 Go (689 Go libre(s) - 100%) [DATA] # NTFS
E:\ -> CD-ROM
K:\ -> Disque amovible # 2 Go (435 Mo libre(s) - 23%) [MEMUP] # FAT
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 480 |ParentID: 472)
C:\Windows\system32\wininit.exe (ID: 528 |ParentID: 472)
C:\Windows\system32\csrss.exe (ID: 556 |ParentID: 536)
C:\Windows\system32\winlogon.exe (ID: 604 |ParentID: 536)
C:\Windows\system32\services.exe (ID: 628 |ParentID: 528)
C:\Windows\system32\lsass.exe (ID: 644 |ParentID: 528)
C:\Windows\system32\lsm.exe (ID: 652 |ParentID: 528)
C:\Windows\system32\svchost.exe (ID: 772 |ParentID: 628)
C:\Windows\system32\nvvsvc.exe (ID: 852 |ParentID: 628)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID: 876 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 924 |ParentID: 628)
C:\Windows\System32\svchost.exe (ID: 264 |ParentID: 628)
C:\Windows\System32\svchost.exe (ID: 344 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 560 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 640 |ParentID: 628)
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (ID: 996 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 1228 |ParentID: 628)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1236 |ParentID: 852)
C:\Windows\system32\nvvsvc.exe (ID: 1244 |ParentID: 852)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1312 |ParentID: 628)
C:\Windows\System32\spoolsv.exe (ID: 1472 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 1652 |ParentID: 628)
C:\Windows\system32\Dwm.exe (ID: 1660 |ParentID: 344)
C:\Windows\Explorer.EXE (ID: 1720 |ParentID: 1640)
C:\Windows\system32\taskhost.exe (ID: 1792 |ParentID: 628)
c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (ID: 2032 |ParentID: 628)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1548 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 1600 |ParentID: 628)
C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe (ID: 1680 |ParentID: 628)
C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (ID: 2000 |ParentID: 628)
C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe (ID: 1224 |ParentID: 772)
C:\Windows\system32\svchost.exe (ID: 2128 |ParentID: 628)
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe (ID: 2208 |ParentID: 628)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2248 |ParentID: 628)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 2328 |ParentID: 1236)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe (ID: 2492 |ParentID: 628)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2500 |ParentID: 2248)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (ID: 2712 |ParentID: 628)
C:\Windows\system32\svchost.exe (ID: 920 |ParentID: 628)
C:\Windows\System32\WUDFHost.exe (ID: 3168 |ParentID: 344)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 3504 |ParentID: 1720)
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (ID: 3572 |ParentID: 1720)
C:\Program Files (x86)\Skype\Phone\Skype.exe (ID: 3772 |ParentID: 1720)
C:\Program Files (x86)\ONconnect\resources\service\win\ONconnect_service.exe (ID: 3876 |ParentID: 1720)
C:\Windows\System32\regsvr32.exe (ID: 3920 |ParentID: 1720)
C:\Windows\SysWOW64\regsvr32.exe (ID: 4008 |ParentID: 3920)
C:\Windows\system32\SearchIndexer.exe (ID: 4052 |ParentID: 628)
C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe (ID: 4080 |ParentID: 3960)
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (ID: 3240 |ParentID: 3960)
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (ID: 3232 |ParentID: 4064)
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (ID: 3512 |ParentID: 3232)
C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUI.exe (ID: 3564 |ParentID: 4080)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 3688 |ParentID: 3960)
C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ID: 3780 |ParentID: 3960)
C:\Windows\System32\svchost.exe (ID: 3720 |ParentID: 628)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 1552 |ParentID: 628)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 2476 |ParentID: 1720)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 2784 |ParentID: 2476)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 5188 |ParentID: 2476)
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (ID: 1284 |ParentID: 2784)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 2848 |ParentID: 772)
C:\Windows\system32\SearchProtocolHost.exe (ID: 2764 |ParentID: 4052)
C:\Windows\system32\SearchFilterHost.exe (ID: 4896 |ParentID: 4052)
C:\Windows\system32\taskeng.exe (ID: 2756 |ParentID: 640)
################## | Regedit Run |
04 - HKLM\..\Run : [Hotkey Utility] C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
04 - HKLM\..\Run : [Boxore Client] C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe
04 - HKLM\..\Run : [Babylon Client] C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
04 - HKLM\..\RunOnce : []
04 - HKLM64\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3045467554-4112737456-3337683980-1001\..\Run : [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
04 - HKU\S-1-5-21-3045467554-4112737456-3337683980-1001\..\Run : [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
04 - HKU\S-1-5-21-3045467554-4112737456-3337683980-1001\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-3045467554-4112737456-3337683980-1001\..\Run : [ONconnectService] C:\Program Files (x86)\ONconnect\resources\service\win\ONconnect_service.exe
04 - HKU\S-1-5-21-3045467554-4112737456-3337683980-1001\..\Run : [Icsoft] regsvr32.exe C:\Users\roullier\AppData\Local\Icsoft\avpcrtPpm.dll
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\..\RunOnce : [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | Recherche générique |
Présent! K:\cold
################## | Registre |
################## | Vaccin |
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |
ça n'a pas de sens pour moi mais ça en aura sans doute pour vous !
Pour l'instant, je n'ai rien tenté car je n'y connais vraiment rien.
Merci de votre aide !