Virus sur msn - Page 2

Résolu
Précédent
  • 1
  • 2
  1. jlys
     
    Bonjour,

    j'ai supprimé avast pour antivir.

    Voici les rapports :

    -Rapport msnfix :

    MSNFix 1.557

    Fix exécuté le 2007-10-30 - 23:01:03.87 By Propriétaire
    mode normal

    ************************ Recherche les fichiers présents

    Aucun Fichier trouvé

    ************************ Recherche les dossiers présents

    Aucun dossier trouvé

    ************************ Fichiers suspects

    /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

    [I:\DotNetInstaller.exe] F89558047E71F655A4DDB99E893213ED

    [color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] I:\DOCUME~1\PROPRI~1\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr

    ------------------------------------------------------------------------
    Auteur : !aur3n7 Contact: https://www.ionos.fr/
    ------------------------------------------------------------------------

    --------------------------------------------- END --------------------

    - Rapport antivir :

    AntiVir PersonalEdition Classic
    Report file date: 2007-10-31 17:57

    Scanning for 910788 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: TANDELEC

    Version information:
    BUILD.DAT : 270 15603 Bytes 2007-09-19 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 2007-08-23 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 2007-08-16 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 2007-08-14 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 2007-08-21 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 14:27:15
    ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 2007-09-13 14:26:55
    ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 2007-10-26 21:53:45
    ANTIVIR3.VDF : 7.0.0.155 93696 Bytes 2007-10-30 16:56:08
    AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 2007-10-30 21:53:45
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 2007-07-18 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 13:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 2007-08-03 08:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 2007-07-18 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 2007-08-28 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 2007-07-18 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 2007-08-07 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 2007-08-21 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 2007-07-23 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: i:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: L:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: 2007-10-31 17:57

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
    Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avgas.exe' - '1' Module(s) have been scanned
    Scan process 'zlclient.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'StarWindServiceAE.exe' - '1' Module(s) have been scanned
    Scan process 'slserv.exe' - '1' Module(s) have been scanned
    Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
    Scan process 'guard.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'vsmon.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    30 processes with 30 modules were scanned

    Start scanning boot sectors:
    Boot sector 'I:\'
    [NOTE] No virus was found!
    Boot sector 'J:\'
    [NOTE] No virus was found!
    Boot sector 'K:\'
    [NOTE] No virus was found!
    Boot sector 'L:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '19' files ).

    Starting the file scan:

    Begin scan in 'I:\' <SYSTEME>
    I:\pagefile.sys
    [WARNING] The file could not be opened!
    I:\Documents and Settings\sulyvann.TANDELEC\Shared\05 Track 5.wma
    [DETECTION] Is the Trojan horse TR/Wimad.A.Gen
    [INFO] The file was moved to '4748b52c.qua'!
    I:\System Volume Information\_restore{C5526F70-41D2-454B-9369-49AD22B780EE}\RP6\A0001049.dll
    [DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
    [INFO] The file was moved to '4758bd87.qua'!
    I:\WINDOWS\system32\drivers\sptd.sys
    [WARNING] The file could not be opened!
    Begin scan in 'J:\' <JEUX>
    Begin scan in 'K:\' <INTERNET>
    Begin scan in 'L:\' <DOCS>

    End of the scan: 2007-10-31 18:55
    Used time: 57:49 min

    The scan has been done completely.

    5902 Scanning directories
    269724 Files were scanned
    2 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    2 files were moved to quarantine
    0 files were renamed
    2 Files cannot be scanned
    269722 Files not concerned
    2221 Archives were scanned
    2 Warnings
    55 Notes

    - Rapport antivir en mode sans échec

    AntiVir PersonalEdition Classic
    Report file date: 2007-10-31 19:23

    Scanning for 910788 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: Propriétaire
    Computer name: TANDELEC

    Version information:
    BUILD.DAT : 270 15603 Bytes 2007-09-19 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 2007-08-23 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 2007-08-16 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 2007-08-14 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 2007-08-21 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 14:27:15
    ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 2007-09-13 14:26:55
    ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 2007-10-26 21:53:45
    ANTIVIR3.VDF : 7.0.0.155 93696 Bytes 2007-10-30 16:56:08
    AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 2007-10-30 21:53:45
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 2007-07-18 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 13:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 2007-08-03 08:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 2007-07-18 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 2007-08-28 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 2007-07-18 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 2007-08-07 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 2007-08-21 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 2007-07-23 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: i:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: L:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: 2007-10-31 19:23

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'guard.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    12 processes with 12 modules were scanned

    Start scanning boot sectors:
    Boot sector 'I:\'
    [NOTE] No virus was found!
    Boot sector 'J:\'
    [NOTE] No virus was found!
    Boot sector 'K:\'
    [NOTE] No virus was found!
    Boot sector 'L:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '24' files ).

    Starting the file scan:

    Begin scan in 'I:\' <SYSTEME>
    I:\pagefile.sys
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\callcont.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\msgina.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\mst120.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\$NtUninstallKB835732$\schannel.dll
    [WARNING] The file could not be opened!
    I:\WINDOWS\system32\drivers\sptd.sys
    [WARNING] The file could not be opened!
    Begin scan in 'J:\' <JEUX>
    Begin scan in 'K:\' <INTERNET>
    Begin scan in 'L:\' <DOCS>

    End of the scan: 2007-10-31 20:29
    Used time: 1:06:01 min

    The scan has been done completely.

    5857 Scanning directories
    268325 Files were scanned
    0 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    16 Files cannot be scanned
    268325 Files not concerned
    2221 Archives were scanned
    16 Warnings
    55 Notes

    Merci pour tout,

    A bientôt.
    0
  2. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    va sur virus total et analyse le fichier suivant:
    https://www.virustotal.com/gui/

    I:\DotNetInstaller.exe

    si il est considéré comme nefaste tu le vire manuellement

    ___________________

    le fichier suivant a été mis en quarantaine: verifie qu'il n'est plus present: dans poste de travail puis C...

    I:\Documents and Settings\sulyvann.TANDELEC\Shared\05 Track 5.wma

    ____________________

    le suivant est dans ta restauration systeme , donc desactive la puis redemarre ton ordi puis reactive la:

    (dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis parametre)

    I:\System Volume Information\_restore{C5526F70-41D2-454B-9369-49AD22B780EE}\RP6\A0001049.dll
    [DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738

    _____________________

    je pense que tu n'es pas infect" mais qu'un de tes contact dois l'etre, demande a tes contacts si ils ont des signes et qu'ils analyse nt avec msnfix leur ordi

    a plus
    0
  3. jlys
     
    Bonjour,

    Je n'ai plus aucun virus.
    je n'ai plus la fenêtre de conversation de msn qui s'ouvre avec le fichier zip, j'ai supprimé le contact et depuis tranquille.

    Moi qui ne connais pas grand chose au pc, tes explications étaient simples à comprendre.

    Je te remercie pour tout, tu as été trés patient.

    Cordialement.
    0
  4. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    parfait
    bonne continuation

    et si pb tu dis

    a plus
    0
Précédent
  • 1
  • 2