Infection win32.brontok
Fermé
gipsie
-
27 juin 2009 à 17:46
Destrio5 Messages postés 85926 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 29 juin 2009 à 17:58
Destrio5 Messages postés 85926 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 29 juin 2009 à 17:58
A voir également:
- Infection win32.brontok
- Hacktool win32 autokms ✓ - Forum Virus / Sécurité
- Win32/lodi - Forum Virus / Sécurité
- Win32:evo-gen - Forum antivirus
- Win32 trojan gen - Forum Virus / Sécurité
- Win32:malware-gen ✓ - Forum Virus / Sécurité
46 réponses
http://www.virustotal.com/fr/analisis/35166560b598f927254657e763508a1c53a7bc1e28763a211cbb2d737cfda9ef-1245395656
voici le rapport de virus total
voici le rapport de virus total
Destrio5
Messages postés
85926
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
29 juin 2009 à 17:34
29 juin 2009 à 17:34
---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.
---> Télécharge OTM (OldTimer) sur ton Bureau.
---> Double-clique sur OTM.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
ZeppelinService
:files
C:\Program Files\Fichiers communs\ParetoLogic
C:\Program Files\ParetoLogic
:reg
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"ParetoLogic Anti-Virus PLUS"=-
:commands
[purity]
[emptytemp]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTM.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
---> Télécharge OTM (OldTimer) sur ton Bureau.
---> Double-clique sur OTM.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
ZeppelinService
:files
C:\Program Files\Fichiers communs\ParetoLogic
C:\Program Files\ParetoLogic
:reg
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"ParetoLogic Anti-Virus PLUS"=-
:commands
[purity]
[emptytemp]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTM.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
Bonjour!
voici le rapport OTM
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
Service\Driver ZeppelinService deleted successfully.
========== FILES ==========
C:\Program Files\Fichiers communs\ParetoLogic\UUS2\Images moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\UUS2 moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine\instdrivers\x32 moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine\instdrivers\w2kxp32 moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine\instdrivers moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAS moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\temp moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\Images moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\HTML\images moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\HTML moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\Help moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS moved successfully.
C:\Program Files\ParetoLogic moved successfully.
========== FILES ==========
File/Folder [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] not found.
File/Folder ParetoLogic Anti-Virus PLUS"= not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: All Users
User: Blanchard
->Temp folder emptied: 78647590 bytes
->Temporary Internet Files folder emptied: 9236265 bytes
->Java cache emptied: 3146651 bytes
->FireFox cache emptied: 49318558 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Gigi
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: Invité
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 552768 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 664 bytes
RecycleBin emptied: 820821 bytes
Total Files Cleaned = 135,19 mb
OTM by OldTimer - Version 3.0.0.2 log created on 06292009_173850
Files moved on Reboot...
Registry entries deleted on Reboot...
voici le rapport OTM
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
Service\Driver ZeppelinService deleted successfully.
========== FILES ==========
C:\Program Files\Fichiers communs\ParetoLogic\UUS2\Images moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\UUS2 moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine\instdrivers\x32 moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine\instdrivers\w2kxp32 moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine\instdrivers moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAVEngine moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic\PLAS moved successfully.
C:\Program Files\Fichiers communs\ParetoLogic moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\temp moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\Images moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\HTML\images moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\HTML moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS\Help moved successfully.
C:\Program Files\ParetoLogic\Anti-Virus PLUS moved successfully.
C:\Program Files\ParetoLogic moved successfully.
========== FILES ==========
File/Folder [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] not found.
File/Folder ParetoLogic Anti-Virus PLUS"= not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: All Users
User: Blanchard
->Temp folder emptied: 78647590 bytes
->Temporary Internet Files folder emptied: 9236265 bytes
->Java cache emptied: 3146651 bytes
->FireFox cache emptied: 49318558 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Gigi
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: Invité
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 552768 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 664 bytes
RecycleBin emptied: 820821 bytes
Total Files Cleaned = 135,19 mb
OTM by OldTimer - Version 3.0.0.2 log created on 06292009_173850
Files moved on Reboot...
Registry entries deleted on Reboot...
Destrio5
Messages postés
85926
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
29 juin 2009 à 17:45
29 juin 2009 à 17:45
Utilise OTM avec ce texte :
:reg
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"ParetoLogic Anti-Virus PLUS"=-
:reg
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"ParetoLogic Anti-Virus PLUS"=-
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ParetoLogic Anti-Virus PLUS deleted successfully.
OTM by OldTimer - Version 3.0.0.2 log created on 06292009_174830
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ParetoLogic Anti-Virus PLUS deleted successfully.
OTM by OldTimer - Version 3.0.0.2 log created on 06292009_174830
Destrio5
Messages postés
85926
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
29 juin 2009 à 17:58
29 juin 2009 à 17:58
Tu as toujours un problème au démarrage ?