Aidez moi svp

Tchoupi51 Messages postés 11 Statut Membre -  
 bernie61 -
Bonjour,

J'ai chopé un virus sur msn et depuis j'ai beau scanner et rescanner, j'arrive pas à m'en débarrasser, ils reviennent. Je ne sais plus quoi faire aidez moi SVP
Voici une partie de mes scanns
4/05/2005,20:27:54 WARNING: Contains signature of the VBS script virus VBS/LoveLetter.D!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\THC2475N\ANVBS[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
14/05/2005,22:19:47 [LOGON] Connection request by remote computer. Establishing secure communication channel.
14/05/2005,22:19:47 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa893b166.
14/05/2005,22:19:57 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\JOCKER[1].EXE
File has been deleted!
14/05/2005,22:20:21 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\WINDOWS\SYSTEM32\JOCKER.EXE
File has been deleted!
14/05/2005,22:20:35 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\QJWFDE3Y\REGULAR_PLUGIN[1].EXE
File has been deleted!
14/05/2005,22:20:41 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\WINDOWS\SYSTEM32\YSBINSTALL_1000489_3.EXE
File has been deleted!
14/05/2005,22:20:29 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
14/05/2005,22:20:50 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
14/05/2005,22:21:29 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
14/05/2005,22:21:32 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
14/05/2005,22:21:57 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
14/05/2005,22:23:11 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:23:16 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:23:20 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
14/05/2005,22:38:28 [LOGON] Connection request by remote computer. Establishing secure communication channel.
14/05/2005,22:38:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa8e0932d.
14/05/2005,22:38:40 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\JOCKER[1].EXE
File has been deleted!
14/05/2005,22:39:01 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\WINDOWS\SYSTEM32\JOCKER.EXE
File has been deleted!
14/05/2005,22:39:10 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\REGULAR_PLUGIN[1].EXE
File has been deleted!
14/05/2005,22:39:18 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\WINDOWS\SYSTEM32\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,00:18:47 [INFO] Stop Filter Device.
15/05/2005,00:18:52 AVGuard service has been stopped!
15/05/2005,00:20:00 ---------------------------------------------------------
15/05/2005,00:20:00 [INIT] The AVGuard Service is starting.
15/05/2005,00:20:09 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,00:20:29 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,00:20:29 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaab80c5.
15/05/2005,00:22:31 [INFO] Start Filter Device.
15/05/2005,00:22:31 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,00:22:32 AVGuard has been started successfully!
15/05/2005,00:25:57 [INFO] Stop Filter Device.
15/05/2005,00:26:03 AVGuard service has been stopped!
15/05/2005,12:42:22 ---------------------------------------------------------
15/05/2005,12:42:22 [INIT] The AVGuard Service is starting.
15/05/2005,12:42:39 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,12:42:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,12:42:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa472d.
15/05/2005,12:43:16 [INFO] Start Filter Device.
15/05/2005,12:44:55 [INFO] Start Filter Device.
15/05/2005,12:44:55 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,12:44:55 AVGuard has been started successfully!
15/05/2005,12:46:57 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\REGULAR_PLUGIN[1].EXE
File has been deleted!
15/05/2005,12:47:13 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,12:46:20 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SHMJW92R\JOCKER[1].EXE
File has been deleted!
15/05/2005,12:47:43 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
15/05/2005,13:04:44 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,13:04:44 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaabf8829.
15/05/2005,13:10:50 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,13:10:50 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaab01244.
15/05/2005,14:00:17 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,14:00:17 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaed540e.
15/05/2005,15:22:52 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,15:22:52 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa39337b.
15/05/2005,16:00:03 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,16:00:03 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa1f0fed.
15/05/2005,16:03:22 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I8M97LCS\PROMPT[1].PHP
File has been deleted!
15/05/2005,16:08:16 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:08:38 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:23 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to move the file to the quarantine directory:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:37 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:43 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:25:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\WEBSITE[1].OCX
15/05/2005,16:25:56 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:01 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:11 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
15/05/2005,16:26:17 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:26:22 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,16:27:15 [INFO] Stop Filter Device.
15/05/2005,16:27:21 AVGuard service has been stopped!
15/05/2005,16:28:15 ---------------------------------------------------------
15/05/2005,16:28:15 [INIT] The AVGuard Service is starting.
15/05/2005,16:28:17 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,16:28:33 [INFO] Start Filter Device.
15/05/2005,16:28:33 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,16:28:33 AVGuard has been started successfully!
15/05/2005,16:37:59 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,16:37:59 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa3d880.
15/05/2005,16:38:26 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\JOCKER[1].EXE
File has been deleted!
15/05/2005,16:38:41 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
15/05/2005,16:39:01 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SHMJW92R\REGULAR_PLUGIN[1].EXE
File has been deleted!
15/05/2005,16:39:07 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
15/05/2005,17:01:26 [INFO] Stop Filter Device.
15/05/2005,17:01:29 AVGuard service has been stopped!
15/05/2005,17:02:22 ---------------------------------------------------------
15/05/2005,17:02:22 [INIT] The AVGuard Service is starting.
15/05/2005,17:02:23 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,17:02:39 [INFO] Start Filter Device.
15/05/2005,17:02:39 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,17:02:39 AVGuard has been started successfully!
15/05/2005,17:10:33 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,17:10:33 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa2ac06.
15/05/2005,17:11:02 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\RAR.EXE
File has been deleted!
15/05/2005,17:11:31 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\VONNER.EXE
File has been deleted!
15/05/2005,17:12:30 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:12:48 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:12:55 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
15/05/2005,17:13:13 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:13:35 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:13:48 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
15/05/2005,17:33:50 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\PROMPT[1].PHP
File has been deleted!
15/05/2005,17:38:48 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
File has been deleted!
15/05/2005,17:38:57 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:13 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:18 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:41 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\P4F6VRLZ\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:46 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:39:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:02 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZMJA7B20\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:06 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,17:40:12 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
15/05/2005,18:20:52 WARNING: Contains signature of the backdoor control software BDC/Gaward.!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\ZZ1591DI\SS3[1].EXE
15/05/2005,18:21:15 WARNING: Contains signature of the backdoor control software BDC/Gaward.!
C:\DOCUMENTS AND SETTINGS\PAULINE00\SS3.EXE
File has been deleted!
15/05/2005,17:46:44 [INFO] Stop Filter Device.
15/05/2005,17:46:52 AVGuard service has been stopped!
15/05/2005,17:47:56 ---------------------------------------------------------
15/05/2005,17:47:56 [INIT] The AVGuard Service is starting.
15/05/2005,17:48:06 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
15/05/2005,17:49:21 [INFO] Start Filter Device.
15/05/2005,17:49:21 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
15/05/2005,17:49:21 AVGuard has been started successfully!
15/05/2005,17:50:57 [LOGON] Connection request by remote computer. Establishing secure communication channel.
15/05/2005,17:50:57 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa9d1a6.
15/05/2005,18:59:26 [INFO] Stop Filter Device.
15/05/2005,18:59:28 AVGuard service has been stopped!
16/05/2005,13:02:27 ---------------------------------------------------------
16/05/2005,13:02:27 [INIT] The AVGuard Service is starting.
16/05/2005,13:02:28 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
16/05/2005,13:02:41 [INFO] Start Filter Device.
16/05/2005,13:02:41 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
16/05/2005,13:02:41 AVGuard has been started successfully!
16/05/2005,13:02:59 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,13:03:00 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa5e38.
16/05/2005,15:39:10 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,15:39:10 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa255a48.
16/05/2005,17:31:26 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,17:31:27 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaa5c1685.
16/05/2005,18:24:58 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,18:24:58 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab8d164d.
16/05/2005,19:39:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,19:39:40 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xabc68a39.
16/05/2005,20:43:56 [LOGON] Connection request by remote computer. Establishing secure communication channel.
16/05/2005,20:43:56 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab0c5ec5.
16/05/2005,20:45:20 [INFO] Stop Filter Device.
16/05/2005,20:45:25 AVGuard service has been stopped!
17/05/2005,12:21:55 ---------------------------------------------------------
17/05/2005,12:21:55 [INIT] The AVGuard Service is starting.
17/05/2005,12:21:56 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,12:22:11 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,12:22:11 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa1849.
17/05/2005,12:22:21 [INFO] Start Filter Device.
17/05/2005,12:22:21 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,12:22:21 AVGuard has been started successfully!
17/05/2005,12:25:32 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SPQLSTS3\PROMPT[1].HTM
File has been deleted!
17/05/2005,12:35:20 [INFO] Stop Filter Device.
17/05/2005,12:35:23 AVGuard service has been stopped!
17/05/2005,15:49:22 ---------------------------------------------------------
17/05/2005,15:49:22 [INIT] The AVGuard Service is starting.
17/05/2005,15:49:30 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,15:49:30 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,15:49:30 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa0769.
17/05/2005,15:49:36 [INFO] Start Filter Device.
17/05/2005,15:49:36 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,15:49:36 AVGuard has been started successfully!
17/05/2005,16:00:52 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,16:01:01 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
17/05/2005,17:50:20 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,17:50:20 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaac5e68e.
17/05/2005,17:50:49 [INFO] Stop Filter Device.
17/05/2005,17:50:58 AVGuard service has been stopped!
17/05/2005,17:51:51 ---------------------------------------------------------
17/05/2005,17:51:51 [INIT] The AVGuard Service is starting.
17/05/2005,17:51:59 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
17/05/2005,17:52:00 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,17:52:00 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa1d53.
17/05/2005,17:52:04 [INFO] Start Filter Device.
17/05/2005,17:52:04 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
17/05/2005,17:52:04 AVGuard has been started successfully!
17/05/2005,17:52:36 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\RAR.EXE
File has been deleted!
17/05/2005,17:52:59 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX1\VONNER.EXE
File has been deleted!
17/05/2005,17:55:53 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\E1SR67G7\PROMPT[1].HTM
File has been deleted!
17/05/2005,18:00:55 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,18:01:02 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,18:04:40 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,18:04:41 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaa6f81b.
17/05/2005,18:04:54 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
17/05/2005,18:05:00 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
17/05/2005,19:00:32 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1URKDEN\WEBSITE[1].OCX
File has been deleted!
17/05/2005,19:15:13 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\I8M97LCS\WEBSITE[1].OCX
File has been deleted!
17/05/2005,18:55:48 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,19:15:20 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
17/05/2005,19:19:45 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6BM9MHS1\PROMPT[1].HTM
File has been deleted!
17/05/2005,19:25:58 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\PROMPT[1].HTM
File has been deleted!
17/05/2005,19:42:08 [LOGON] Connection request by remote computer. Establishing secure communication channel.
17/05/2005,19:42:08 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaacf2661.
18/05/2005,01:32:22 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,01:32:23 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xab0c9f65.
18/05/2005,08:27:41 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,08:27:41 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa988c715.
18/05/2005,10:28:21 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,10:28:21 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xa93a4d76.
18/05/2005,13:17:24 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,13:17:25 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae811a92.
18/05/2005,13:42:03 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDMZ016R\JOCKER[1].EXE
File has been deleted!
18/05/2005,13:44:50 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
18/05/2005,13:44:38 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
Unable to delete the file:
0x00000002 - Le fichier spécifié est introuvable.
18/05/2005,13:44:04 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
Unable to delete the file:
0x00000002 - Le fichier spécifié est introuvable.
18/05/2005,14:52:45 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,14:52:45 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae28536a.
18/05/2005,15:52:47 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,15:52:47 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xae134644.
18/05/2005,18:41:01 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,18:41:01 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaff95fc3.
18/05/2005,21:42:17 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,21:42:18 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaf53403a.
18/05/2005,21:48:37 [INFO] Stop Filter Device.
18/05/2005,21:48:44 AVGuard service has been stopped!
18/05/2005,23:02:57 ---------------------------------------------------------
18/05/2005,23:02:57 [INIT] The AVGuard Service is starting.
18/05/2005,23:03:18 [INIT] Keyfile contains a valid license. The AVGuard service will run as a fully functional version!
18/05/2005,23:03:19 [LOGON] Connection request by remote computer. Establishing secure communication channel.
18/05/2005,23:03:19 [LOGON] Connection to computer 127.0.0.1 established successfully. Session ID = 0xaaaa570f.
18/05/2005,23:03:38 [INFO] Start Filter Device.
18/05/2005,23:03:38 AntiVirService Version: 6.30.00.06 AVE Version 6.30.0.12 VDF Version: 6.30.0.177
18/05/2005,23:03:38 AVGuard has been started successfully!
18/05/2005,23:05:16 WARNING: Is the Trojan horse TR/Dldr.IstBar.IQ!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
18/05/2005,23:05:28 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
18/05/2005,23:05:55 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NFTQIYRZ\JOCKER[1].EXE
File has been deleted!
18/05/2005,23:05:58 WARNING: Is the Trojan horse TR/Dldr.Small.YA.2!
C:\DOCUMENTS AND SETTINGS\PAULINE00\JOCKER.EXE
File has been deleted!
18/05/2005,23:06:56 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\NFTQIYRZ\REGULAR_PLUGIN[1].EXE
File has been deleted!
18/05/2005,23:06:58 WARNING: Is the Trojan horse TR/Dldr.IstBar.IT!
C:\DOCUMENTS AND SETTINGS\PAULINE00\YSBINSTALL_1000489_3.EXE
File has been deleted!
18/05/2005,23:07:10 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:08:08 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:09:26 WARNING: Is the Trojan horse TR/Qhosts.Script.A!
C:\WINDOWS\SYSTEM32\HOSTS
File has been deleted!
18/05/2005,23:09:31 WARNING: Contains signature of the worm Worm/Randon.AB.4!
C:\WINDOWS\SYSTEM32\PALSP.EXE
File has been deleted!
18/05/2005,23:09:34 WARNING: Contains a signature of the (dangerous) backdoor program BDS/HacDef.073.B.4 Backdoor server programs !
C:\WINDOWS\SYSTEM32\ZEMA
File has been deleted!
18/05/2005,23:10:32 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
18/05/2005,23:12:47 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
18/05/2005,23:13:11 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
18/05/2005,23:13:28 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!

14 réponses

balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
salut
utilise ceci et ensuite refait un scan
a faire hors connection
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe
0
Tchoupi51 Messages postés 11 Statut Membre
 
J'ai déjà fait et les virus reviennent quand même.
Tu n'as pas une autre solution?
Merci d'avance
0
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
fait le
refait un scan met moi le resultat
et a tu anti virus et pare feu
0
Tchoupi51 Messages postés 11 Statut Membre
 
voici mon scann avec clean up

CleanUp! started on 05/19/05 15:55:12.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
'Typed URLs' (Internet Explorer) - removed from the registry.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Pauline00\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf - deleted
C:\WINDOWS\Prefetch\LAUNAPP.EXE-2728A3F2.pf - deleted
C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf - deleted
C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf - deleted
C:\WINDOWS\Prefetch\IGFXTRAY.EXE-3391579A.pf - deleted
C:\WINDOWS\Prefetch\HKCMD.EXE-1D05234B.pf - deleted
C:\WINDOWS\Prefetch\SYNTPLPR.EXE-28BB9F3B.pf - deleted
C:\WINDOWS\Prefetch\SYNTPENH.EXE-315D3ABC.pf - deleted
C:\WINDOWS\Prefetch\LAUNCHAP.EXE-04C655F4.pf - deleted
C:\WINDOWS\Prefetch\HOTKEYAPP.EXE-33C84604.pf - deleted
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! recovered 154.2 KB of disk space from 10 files.
CleanUp! finished on 05/19/05 15:55:14.

Le problème c'est que quand je redémarre les fichiers ne se suppriment pas.
Merci pour vos solutions
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
balltrap34 Messages postés 16241 Statut Contributeur sécurité 332
 
fait un scan ici ont i verrat plus clair
Faite scan en ligne et coller le rapport ici sur le post
utiliser l'antivirus en ligne suivant :
http://www.ravantivirus.com/scan/
Cliquer sur "To continue without subscribing click here" et attendre quelques minutes.

Lorsque "Ready" est affiché dans "status", cocher la case "Autoclean" puis cliquer sur "Scan my PC"
A la fin de l'analyse, copier/coller le rapport ici.
0
Tchoupi51 Messages postés 11 Statut Membre
 
Mon ordinateur ne veut pas accéder à l'antivirus en ligne. J'ai essayer celui de Secuser aussi et ça n'a pas marché. Il me dit que les paramètres de sécurité de mon ordinateur ne me permettent pas d'accéder aux pages.
Et Antivir continue de me détecter ces virus...
0
Utilisateur anonyme
 
Antivir te les detecte ou?
0
bernie61
 
salut à tous
tchoupi relances cleanup puis antivir mais en mode sans échec (hors connection) pour effacer plus facilement, ensuite si toujours pas clean fais ceci
* tu charges Sysclean Package là:
http://fr.trendmicro-europe.com/enterprise/support/tsc.php
et le fichier dernière version signatures virus « LTPxxx.ZIP » (xxx représente les chiffres indiquant la version ) là
http://fr.trendmicro-europe.com/enterprise/support/pattern.php
*tu décomprimes le ltpxxx.zip et place le fichier ltp$vpn.xxx dans le même répertoire que Sysclean
* tu redémarres en mode sans échec
*tu lances le scan en cliquant sur sysclean.com et il est créé un fichier sysclean.log dans ce répertoire ;
a+
0
Tchoupi51 Messages postés 11 Statut Membre
 
voici un apercu de mon dernier scann qui est encore en cours
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\RAR.EXE
File has been deleted!
19/05/2005,21:26:22 WARNING: Is the Trojan horse TR/StartPage.nk.8.B!
C:\DOCUME~1\PAULIN~1\LOCALS~1\TEMP\RARSFX0\VONNER.EXE
File has been deleted!
19/05/2005,21:26:56 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
19/05/2005,21:29:01 WARNING: Is the Trojan horse TR/Drop.180Soluti.A!
C:\TEMP\NCASEPACKAGE.EXE
File has been deleted!
19/05/2005,21:31:16 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:32:06 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:32:19 WARNING: Is the Trojan horse TR/Dldr.Dyfuca.ds!
C:\TEMP\OPTIMIZE.EXE
File has been deleted!
19/05/2005,21:34:04 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CDABK9EN\PROMPT[1].HTM
File has been deleted!
19/05/2005,22:04:29 WARNING: Contains signature of the HTML script virus HTML/IstBar.A.1!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\63EB6D63\PROMPT[1].HTM
File has been deleted!
19/05/2005,22:10:14 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
19/05/2005,22:10:23 WARNING: Is the Trojan horse TR/Dldr.Agent.EX!
C:\DOCUMENTS AND SETTINGS\PAULINE00\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\IIZX1BX7\WEBSITE[1].OCX
Unable to delete the file:
0x00000020 - Le processus ne peut pas accéder au fichier car ce f
0
bernie61
 
salut
regardes dans Démarrer/panneauConfig/ajoutSupressionProgrammes
si tu as 180solutions et désinstalles ou bien un log similaire, Dyfuca, Bagains, une toolbar (mais pas n'importe laquelle dis nous quoi), etc...
sinon dans C:ProgramFiles/180solution... ou les autres ou un pgm que tu connais pas et dis nous quoi
tu pourrais effacer complètement le répertoire en question
a+
0
maccrtney
 
je vais suivre de tres pres vos conseils je crois avoir exactement le meme blem et de plus quand j'ouvre msn les fenetres de mes contacts connectes s'ouvrent d'1 seul coup et leurs envoient 1 adresse http antivir detect sans des trojean du meme type que tchoupi je crois et bit defender n'arrive pas àles effacer ils les deplacent merci pour les solutions que vous apporterez merciiiiiiiiiiiiiii!!!!!!!!!
0
Tchoupi51 Messages postés 11 Statut Membre
 
Je ne trouve aucun de ces noms.

Si vous aviez une autre solution ce serait vraiment très gentil

Merci
0
Utilisateur anonyme
 
salut tchoupi:
vide tes fichiers temps et tempory internet file sur tous les utilisateur
utilise ceci pour le faire
http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

ensuite verifie les releve d antivir et colle les ici qd tu as une detection !

ou sinon:
http://housecall-beta.trendmicro.com/en/start_corp.asp

lance un scan ici

a+
0
bernie61
 
re salut à tous
tchoupi, installes AdAware et Spybot , mettre à jour et scan avec tu effaces/coches tout ce qu'ils trouvent
anti adware de lavasoft là gratuit AdAware-SE
http://www.lavasoftusa.com/support/download/
Et SpySwepper là :
http://www.webroot.com/products/spysweeper/ free 1mois puis payant
http://www.pctools.com/spyware-doctor/ scan en ligne+download gratuit 15j puis payant pour update
et SpySubtract (gratuit 1 mois)
http://www.intermute.com/products/spysubtract.html
et surtout celui là Spybot S&D là: (free) version 1.4beta2
http://www.softpedia.com/progDownload/SpyBot--Search--Destroy--beta-Download-1865.html

Recherche aussi OptimizeInternet et si tu trouves tu désinstalles ou effaces tout le répertoire
a+
0