zadfdc
Messages postés1Date d'inscriptionmercredi 6 décembre 2006StatutMembreDernière intervention 6 décembre 2006
-
6 déc. 2006 à 16:47
Regis59
Messages postés21143Date d'inscriptionmardi 27 juin 2006StatutContributeur sécuritéDernière intervention22 juin 2016
-
6 déc. 2006 à 18:52
Bonjour à tous,
Depuis ce matin, Norton me signale toutes les cinq minutes la présence du virus Bloodhound.W32.EP, dans le répertoire C:\DOCUME~1\REGIS\LOCALS~1\TEMP\4.exe.
J'ai donc fait un scan Hijackthis, qui donne ça:
Logfile of HijackThis v1.99.1
Scan saved at 16:45:48, on 06/12/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Et surtout un kapersky, alarmiste au possible, qui donne ça:
KASPERSKY ONLINE SCANNER REPORT
Wednesday, December 06, 2006 4:34:58 PM
Operating System: Microsoft Windows XP Home Edition, (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 6/12/2006
Kaspersky Anti-Virus database records: 234441
Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 65949
Number of viruses found 13
Number of infected objects 113 / 0
Number of suspicious objects 0
Duration of the scan process 01:40:34
Infected Object Name Virus Name Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\9AR82985\drsmartload556a[1].exe Infected: Trojan-Downloader.Win32.Adload.as skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\Régis\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Temp\mhs.dll Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Temp\62601.exe Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Temp\mhs2.dll Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Temp\48151.exe Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Temp\zts2.dll Infected: Trojan-PSW.Win32.OnLineGames.cj skipped
C:\Documents and Settings\Régis\Local Settings\Temp\19433.exe Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Temp\mhs.exe Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Temp\zbnzyvvt.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\tmncdywy.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\czlkbazi.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\bnwvitrj.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\oilvwkgk.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\aizvgqyx.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\ynmpwgwp.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\htdxwtty.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\ispkpain.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\ioufqedq.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\dsxvoscx.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\aagqyjep.dll Infected: Trojan-PSW.Win32.OnLineGames.cr skipped
C:\Documents and Settings\Régis\Local Settings\Temp\~DFA22B.tmp Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Historique\History.IE5\MSHist012006120620061207\index.dat Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Temporary Internet Files\Content.IE5\4LUV456N\zt[1].exe Infected: Trojan-PSW.Win32.OnLineGames.cj skipped
C:\Documents and Settings\Régis\Local Settings\Temporary Internet Files\Content.IE5\Z44LOEJY\mh2[1].exe Infected: Trojan-PSW.Win32.OnLineGames.bs skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Identities\{585D1AFE-9F4D-4877-A4E5-855ED71C3788}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Identities\{585D1AFE-9F4D-4877-A4E5-855ED71C3788}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Identities\{585D1AFE-9F4D-4877-A4E5-855ED71C3788}\Microsoft\Outlook Express\cleanup.log Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Identities\{585D1AFE-9F4D-4877-A4E5-855ED71C3788}\Microsoft\Outlook Express\Pop3uidl.dbx Object is locked skipped
C:\Documents and Settings\Régis\Local Settings\Application Data\Identities\{585D1AFE-9F4D-4877-A4E5-855ED71C3788}\Microsoft\Outlook Express\Boîte de réception.dbx Object is locked skipped
C:\Documents and Settings\Régis\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Régis\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
C:\Documents and Settings\Régis\ntuser.dat Object is locked skipped