G le virus TR/Dialer.FU.1 je narrive pas a le

Résolu
massyu -  
nylonmoon Messages postés 1 Statut Membre -
s'il vous plait aider moi pour enlever le virus Tr/dialer.FU.1 j'ai déjas essayer avc antivir et ad-aware se personal mais sans résultat je vous remercie d'avance.
A voir également:

6 réponses

Utilisateur anonyme
 
salut,

1/lance un scan chez RAV :
http://www.ravantivirus.com/scan/

Clique sur "To continue without subscribing click here" et attends quelques minutes.
Lorsque "Ready" est affiché dans "status", coche la case "Autoclean" puis clique sur "Scan my PC"
A la fin de l'analyse, copie/colle le rapport ici

Je vais essayer de t aider...a+
0
OnlyKev Messages postés 96 Statut Membre 5
 
Bonjour,
De toute facon ce virus n'est pas tres dangereux puisqu'il permet au hacker d'utiliser tes communications telephoniques (il me semble). Donc si tu ne te connecte pas sur ta prise telephonique directemant c'est pas bien grave...
0
Utilisateur anonyme
 
d'utiliser tes communications telephoniques < et la facture de tel? qui la paie lol
0
massyu Messages postés 3 Statut Membre
 
c moi ki les paye les communication téléphonique pourkoi le virus c pour les appelle sa craint il faut ke je l'enleve ou ma facture va etre trop chere. c avec cegetel ki s'occuppe de mes facture téléphonique
0
massyu Messages postés 3 Statut Membre
 
Creation date of the report file: jeudi 12 mai 2005 11:51

AntiVir®/XP (2000 + NT) PersonalEdition Classic Build 1035, 16.03.2005
Mainprogram 6.30.00.17 of 07.03.2005
VDF file 6.30.0.173 (0) of 12.05.2005


This program is for PERSONAL USE only.
Any other use is PROHIBITED.
Informations regarding commercial versions of AntiVir may be obtained from:
www.antivir-pe.com.


Scanning for 168845 virus strains and unwanted programs.

Licensed for: AntiVir Personal Edition
Serial number: 0000149996-ADJIE-0001
FUSE: Basic license

Please enter the workstation and
contact name with phone number in this form:

Name ___________________________________________

Street ___________________________________________

Town ___________________________________________

Phone/Fax ___________________________________________

Email ___________________________________________

Platform: Windows NT Workstation
Windows version: 5.1 Build 2600 (Service Pack 1)
Username: massy
Processor: Pentium
Working memory: 720368 KB free

Version information:
AVWIN.DLL : 6.30.00.17 561192 08.03.2005 15:04:34
AVEWIN32.DLL : 6.30.0.12 819712 09.05.2005 11:09:36
AVGNT.EXE : 6.30.00.01 163943 17.02.2005 11:53:00
AVGUARD.EXE : 6.30.00.06 240168 01.03.2005 15:19:26
GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 10:24:10
AVGCMSG.DLL : 6.30.00.01 290933 02.02.2005 09:51:48
AVGNTDW.SYS : 6.30.00.04 32640 28.01.2005 11:55:42
AVPACK32.DLL : 6.30.0.9 319568 12.04.2005 10:16:50
AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 17:10:20
AVWIN.DLL : 6.30.00.17 561192 08.03.2005 15:04:34
AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 17:10:22
AVSched32.EXE : 6.30.00.00 110632 01.02.2005 10:24:10
AVSched32.DLL : 6.30.00.00 122880 01.02.2005 10:24:10
AVREG.DLL : 6.30.00.03 41000 10.02.2005 17:47:48
AVRep.DLL : 6.30.00.170 1105960 11.05.2005 12:19:02
INETUPD.EXE : 6.30.00.17 266299 08.03.2005 15:04:34
INETUPD.DLL : 6.30.00.17 143360 08.03.2005 15:04:34
CTL3D32.DLL : 2.31.000 27136 28.08.2001 14:00:00
MFC42.DLL : 6.00.8665.0 995383 28.08.2001 14:00:00
MSVCRT.DLL : 7.0.2600.1106 (xpsp1.020828-1920
MSVCRT.DLL : 7.0.2600.1106 323072 29.08.2002 11:44:52
CTL3DV2.DLL : No information

Configuration file:

Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI
Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG
Start path: C:\Program Files\AVPersonal
Command line: /S*H*L="C:\"
Start mode: Shell extension

Mode of report file:
[ ] Do not create report
[X] Overwrite report
[ ] Append new report

Data in report file:
[X] Infected files
[ ] Infected files with paths
[ ] All scanned files
[ ] Full information

Abridge report file:
[ ] Abridge report file

Warnings in report:
[X] Access denied/file locked
[X] Wrong file size in directory
[X] Wrong creation time in directory
[ ] COM file is too large
[X] Invalid start address
[X] Invalid EXE header
[X] Possibly damaged

Summary report:
[X] Create summary report
Output file: AVWIN.ACT
Maximum number of entries: 100

Where to search:
[X] Memory
[X] Boot record of selected drives
[ ] Report unknown boot sectors
[ ] All files
[X] Program files
Extensions: .386 .?HT* .ACM .ADE .ADP .ANI .APP .ASD .ASF .ASP .ASX .AWX .AX .BAS .BAT .BIN .BOO .CDF .CHM .CLASS .CMD .CNV .COM .CPL .CRT .CSH .DLL .DLO .DO? .DRV .EMF .EML .EXE* .FLT .FOT .HLP .HT* .INF .INI .INS .ISP .J2K .JAR .JFF .JFI .JFIF .JIF .JMH .JNG .JP2 .JPE .JPEG .JPG .JS* .JSE .LNK .MD? .MDB .MOD .MS? .NWS .OBJ .OCX .OLB .OSD .OV? .PCD .PDR .PGM .PHP .PIF .PKG .PL* .PNG .POT .PPS .PPT .PRG .RAR .REG .RPL .RTF .SBF .SCR .SCRIPT .SCT .SH .SHA .SHB .SHS .SHTM* .SPL .SWF .SYS .TLB .TMP .TSP .TTF .URL .VB? .VCS .VLM .VXD .VXO .WIZ .WLL .WMD .WMS .WMZ .WPC .WSC .WSF .WSH .WWK .XL? .XML .ZIP

Response in case of a detection:
[X] Repair with prompt
[ ] Repair without prompt
[ ] Delete with prompt
[ ] Delete without prompt
[ ] Write in report file only
[X] Acoustic alarm

Response in case of destroyed files:
[X] Delete with prompt
[ ] Delete without prompt
[ ] Ignore

Response in case of destroyed files:
[X] No change
[ ] Current system time
[ ] Correct date

Drag&drop settings:
[X] Scan subdirectories

Profile settings:
[X] Scan subdirectories

Archive options
[X] Search archive
[X] All archive types

Miscellaneous options:
Temporary path: %TEMP% -> C:\DOCUME~1\massy\LOCALS~1\Temp
[X] Overwrite infected files
[ ] Detect idle time
[X] Allow interruptions of scan
[X] Load AVWin®/NT Guard on System start

General settings:
[X] Save options on exiting AntiVir
Priority: medium

Start of scan: jeudi 12 mai 2005 11:51

Memory test OK
Master boot record of hard disk HD0 OK
Boot record of drive C: OK
Boot record of drive C: OK





C:\
pagefile.sys
Access denied! Error during file opening!
This is a Windows swap file. This file is locked by Windows.
Error code: 0x000D
WARNING! Access error/file locked!
C:\Documents and Settings\massy\Local Settings\Temporary Internet Files\Content.IE5\GXKH8ZIZ
SysWebTelecomInt[1].cab
ArchiveType: CAB (Microsoft)
--> sponsoradulto.dll
[DETECTION] Is the Trojan horse TR/Dialer.FU.1
C:\Program Files\WinRAR
rarnew.dat
ArchiveType: RAR
NOTE! The archive is created by multiple volumes
Error! Could not change directory: System Volume Information
C:\WINDOWS\system32\config
default
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SAM
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SECURITY
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
software
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
system
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!

End of scan: jeudi 12 mai 2005 12:02
Time taken: 10:50 min


2116 directories were scanned
37154 files were scanned
6 warning messages were issued
0 files were deleted
0 files were repaired
1 detection

sa c'est le rapport d'antivir mon antivirus si tu peut faire kelke chose sa serait de la bal je te remercie d'avance avec rav antivirus sa a pas voulut scanner. Avant javait la ligne téléphonique avec l'ADSL mais depuis que g lut le message du collègue g mis le téléphone dans une ligne et l'ADSL tout seul,voila merci a tous.
0
Utilisateur anonyme
 
bjr,
essai ceci stp:
vide tes fichiers temps et tempory internet file sur tous les utilisateur
utilise ceci pour le faire
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

Tu l installes puis scan avec il va te supprimer pas mal de trucs et ensuite redemarre...

as tu tjr la detection?

Tiens moi au courant
0
massyu Messages postés 3 Statut Membre
 
franchement tes un artiste g rescanner aver antivir et le virus a disparu. Sa marche bien ton truc je te remercie beaucoup regis sa ma beaucoup aider car sa commencer a me souler. A la prochaine et merci encore.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
 
ok de rien !
cet utilitaire supprime ce qui a dans tes fichiers temp ainsi si ton antivirus detecte ds un fichier temp, passe le un coup et voila

a+
0
nylonmoon Messages postés 1 Statut Membre
 
Bonjour

je suis nouveau sur le forum et j'ai tt essayé pour éradiquer le virus: spybot, clean up... mon antivirus le repère a chaque démarrage je ne sais plus quoi faire.

Voivi le rapport de mon antivirus:

AntiVir PersonalEdition Classic
Report file date: jeudi 9 août 2007 15:39

Scanning for 991574 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Frederic
Computer name: PACKARD-BE9A752

Version information:
BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 07/07/2007 17:41:38
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 20:19:55
ANTIVIR2.VDF : 6.39.0.194 975360 Bytes 28/07/2007 16:07:06
ANTIVIR3.VDF : 6.39.0.195 2048 Bytes 28/07/2007 16:07:06
AVEWIN32.DLL : 7.4.0.50 2650624 Bytes 26/08/2007 10:36:10
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.13 360488 Bytes 07/07/2007 17:41:39
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 07/07/2007 17:41:38
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42

Configuration settings for the scan:
Jobname..........................: Local Drives
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: I:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: jeudi 9 août 2007 15:39

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'X10nets.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
28 processes with 28 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'E:\'
[NOTE] In the drive 'E:\' no data medium is inserted!
Boot sector 'F:\'
[NOTE] In the drive 'F:\' no data medium is inserted!
Boot sector 'G:\'
[NOTE] In the drive 'G:\' no data medium is inserted!
Boot sector 'H:\'
[NOTE] In the drive 'H:\' no data medium is inserted!

Starting to scan the registry.
The registry was scanned ( '14' files ).

Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\' <Données>
Begin scan in 'E:\'
Search path E:\ could not be opened!
Le périphérique n'est pas prêt.

Begin scan in 'F:\'
Search path F:\ could not be opened!
Le périphérique n'est pas prêt.

Begin scan in 'G:\'
Search path G:\ could not be opened!
Le périphérique n'est pas prêt.

Begin scan in 'H:\'
Search path H:\ could not be opened!
Le périphérique n'est pas prêt.

Begin scan in 'I:\'
Search path I:\ could not be opened!
Le périphérique n'est pas prêt.

End of the scan: jeudi 9 août 2007 15:52
Used time: 13:06 min

The scan has been done completely.

2557 Scanning directories
129547 Files were scanned
0 viruses and/or unwanted programs were found
0 classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
129547 Files not concerned
1779 Archives were scanned
1 Warnings
71 Notes
0 Hidden objects were found
0