yellowfox
Messages postés1Date d'inscriptionmardi 24 juillet 2007StatutMembreDernière intervention24 juillet 2007
-
24 juil. 2007 à 15:12
Timothé Balguerie -
24 juil. 2007 à 15:20
Bonjour à tous !!! j'ai suivi les recommandations d'usage suite à des pertes de connexion sauvages et ma crainte d'avoir chopé un trojan , et j'ai effectué les 6 manoeuvres prealables avant de créer mon sujet :
1/ Adaware
2/Spybot
3/Ewido en fait AVG Anti Spyware ( et auomatiquement avec la version 7.5 il m'a m^me remplacé mon ancien antivirus Antivir )
4/CC Cleaner
5/Scan OnLine BitDefender
6/ HijackThis
-------------------
Voici les logs :
A² : ( pas moyen d'installer ewido ) :
[quote]a-squared Free - Version 2
Scan settings:
Objects: Memory, Traces, Cookies, C:\, D:\
Scan archives: On
Heuristics: Off
ADS Scan: On
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 158)=>[Subject: Undelivered Mail Returned to Sender][Date: Mon, 11 Apr 2005 23:25:14 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: patched][Date: Mon, 11 Apr 2005 23:25:11 +0200]=>(MIME part)=>information.zip=>archstored:details.txt .pif
Infected with: Win32.Netsky.P@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 158)=>[Subject: Undelivered Mail Returned to Sender][Date: Mon, 11 Apr 2005 23:25:14 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: patched][Date: Mon, 11 Apr 2005 23:25:11 +0200]=>(MIME part)=>information.zip=>archstored:details.txt .pif
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 158)=>[Subject: Undelivered Mail Returned to Sender][Date: Mon, 11 Apr 2005 23:25:14 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: patched][Date: Mon, 11 Apr 2005 23:25:11 +0200]=>(MIME part)=>information.zip
Update failed
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 249)=>[Subject: Undelivered Mail Returned to Sender][Date: Mon, 2 May 2005 23:47:22 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: word document][Date: Mon, 2 May 2005 23:47:30 +0200]=>(MIME part)=>document_marguiazam.zip=>archstored:document.txt .exe
Infected with: Win32.Netsky.P@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 249)=>[Subject: Undelivered Mail Returned to Sender][Date: Mon, 2 May 2005 23:47:22 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: word document][Date: Mon, 2 May 2005 23:47:30 +0200]=>(MIME part)=>document_marguiazam.zip=>archstored:document.txt .exe
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 249)=>[Subject: Undelivered Mail Returned to Sender][Date: Mon, 2 May 2005 23:47:22 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: word document][Date: Mon, 2 May 2005 23:47:30 +0200]=>(MIME part)=>document_marguiazam.zip
Update failed
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 275)=>[Subject: Undelivered Mail Returned to Sender][Date: Sat, 7 May 2005 19:03:48 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: Proof of concept][Date: Sat, 7 May 2005 19:03:55 +0200]=>(MIME part)=>part_01.zip=>archstored:document.txt .exe
Infected with: Win32.Netsky.P@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 275)=>[Subject: Undelivered Mail Returned to Sender][Date: Sat, 7 May 2005 19:03:48 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: Proof of concept][Date: Sat, 7 May 2005 19:03:55 +0200]=>(MIME part)=>part_01.zip=>archstored:document.txt .exe
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 275)=>[Subject: Undelivered Mail Returned to Sender][Date: Sat, 7 May 2005 19:03:48 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: Proof of concept][Date: Sat, 7 May 2005 19:03:55 +0200]=>(MIME part)=>part_01.zip
Update failed
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 366)=>[Subject: Undelivered Mail Returned to Sender][Date: Thu, 26 May 2005 20:01:54 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Private document][Date: Thu, 26 May 2005 20:02:03 +0200]=>(MIME part)=>document342.zip=>archstored:data.rtf .scr
Infected with: Win32.Netsky.P@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 366)=>[Subject: Undelivered Mail Returned to Sender][Date: Thu, 26 May 2005 20:01:54 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Private document][Date: Thu, 26 May 2005 20:02:03 +0200]=>(MIME part)=>document342.zip=>archstored:data.rtf .scr
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 366)=>[Subject: Undelivered Mail Returned to Sender][Date: Thu, 26 May 2005 20:01:54 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Private document][Date: Thu, 26 May 2005 20:02:03 +0200]=>(MIME part)=>document342.zip
Update failed
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 456)=>[Subject: Undelivered Mail Returned to Sender][Date: Tue, 14 Jun 2005 23:59:53 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: A!p$ghsa][Date: Tue, 14 Jun 2005 23:59:55 +0200]=>(MIME part)=>details03.zip=>archstored:document.txt .exe
Infected with: Win32.Netsky.P@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 456)=>[Subject: Undelivered Mail Returned to Sender][Date: Tue, 14 Jun 2005 23:59:53 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: A!p$ghsa][Date: Tue, 14 Jun 2005 23:59:55 +0200]=>(MIME part)=>details03.zip=>archstored:document.txt .exe
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 456)=>[Subject: Undelivered Mail Returned to Sender][Date: Tue, 14 Jun 2005 23:59:53 +0200 (CEST)]=>(MIME part)=>(message)=>[Subject: Re: A!p$ghsa][Date: Tue, 14 Jun 2005 23:59:55 +0200]=>(MIME part)=>details03.zip
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 901)
Updated
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox
Updated
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 1079)=>(base64)
Infected with: Win32.Netsky.Y@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 1079)=>(base64)
Disinfection failed
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 1079)=>(base64)
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 1079)
Updated
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox
Updated
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 2410)=>[Subject: Mail server report.][Date: :?, 22 2006 20:00:42 +0800]=>(MIME part)=>Update-KB9140-x86.exe
Infected with: Win32.Warezov.GC@mm
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 2410)=>[Subject: Mail server report.][Date: :?, 22 2006 20:00:42 +0800]=>(MIME part)=>Update-KB9140-x86.exe
Disinfection failed
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 2410)=>[Subject: Mail server report.][Date: :?, 22 2006 20:00:42 +0800]=>(MIME part)=>Update-KB9140-x86.exe
Deleted
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 2410)=>[Subject: Mail server report.][Date: :?, 22 2006 20:00:42 +0800]=>(MIME part)
Updated
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox=>(message 2410)
Updated
C:\Documents and Settings\Jean-Mi\Application Data\Thunderbird\Profiles\3ghb8vop.default\Mail\pop.free.fr\Inbox
Updated
C:\Documents and Settings\Jean-Mi\Local Settings\Application Data\Identities\{C8F49FA7-1A37-471B-AE5A-49F0909D666A}\Microsoft\Outlook Express\Hotmail - Courrier indésirable.dbx=>(message 0)=>[From: Online Rx][Date: 10 Mar 2007 07:17:06 -0800]=>(MIME part)=>uima.html
Infected with: Trojan.JS.Redirector.B
C:\Documents and Settings\Jean-Mi\Local Settings\Application Data\Identities\{C8F49FA7-1A37-471B-AE5A-49F0909D666A}\Microsoft\Outlook Express\Hotmail - Courrier indésirable.dbx=>(message 0)=>[From: Online Rx][Date: 10 Mar 2007 07:17:06 -0800]=>(MIME part)=>uima.html
Disinfection failed
C:\Documents and Settings\Jean-Mi\Local Settings\Application Data\Identities\{C8F49FA7-1A37-471B-AE5A-49F0909D666A}\Microsoft\Outlook Express\Hotmail - Courrier indésirable.dbx=>(message 0)=>[From: Online Rx][Date: 10 Mar 2007 07:17:06 -0800]=>(MIME part)=>uima.html
Deleted
C:\Documents and Settings\Jean-Mi\Local Settings\Application Data\Identities\{C8F49FA7-1A37-471B-AE5A-49F0909D666A}\Microsoft\Outlook Express\Hotmail - Courrier indésirable.dbx=>(message 0)=>[From: Online Rx][Date: 10 Mar 2007 07:17:06 -0800]=>(MIME part)
Updated
C:\Documents and Settings\Jean-Mi\Local Settings\Application Data\Identities\{C8F49FA7-1A37-471B-AE5A-49F0909D666A}\Microsoft\Outlook Express\Hotmail - Courrier indésirable.dbx=>(message 0)
Updated
C:\Documents and Settings\Jean-Mi\Local Settings\Application Data\Identities\{C8F49FA7-1A37-471B-AE5A-49F0909D666A}\Microsoft\Outlook Express\Hotmail - Courrier indésirable.dbx
Update failed[/quote]
et le log HijackThis :
[quote]Logfile of HijackThis v1.99.1
Scan saved at 20:24:30, on 23/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Salut, je te conseil de tout d'éffectuer tout l'acrticle sur ce blog pour nettoyer ton PC : http://aide-windows.over-blog.com/article-11026109.html Bonne chance !