Virus trojan ne veut pas partir - Page 2

Précédent
  • 1
  • 2
  1. g!rly Messages postés 18462 Statut Contributeur 407
     
    re,

    bon tu peux supprimer les trois fichiers :

    Télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
    double-click sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    Citation :

    C:\WINDOWS\system32\hvukulap.exe
    C:\WINDOWS\system32\bsajxme.exe
    C:\WINDOWS\system32\snulfz.exe

    Click sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    click sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
    Ps : il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
    http://img137.imageshack.us/img137/3558/refaitjk8.th.jpg

    et essaie de trouver et anlayser celui la en fesant ceci :

    C:\WINDOWS\system32\winsp32.exe

    Affiche tous les fichiers et dossiers :
    Pour cela :
    Clique sur démarrer/panneau de configuration/option des dossiers/affichage

    Cocher afficher les dossiers cacher

    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

    Décocher masquer les extensions dont le type est connu

    Puis fais «Ok» pour valider les changements.

    Et appliquer !

    tu as la version personnel (gratuite) d´avg ?

    post le rapport de ot -Move it ainsi que celui de jottis
    0
  2. jackbenoit
     
    Jai trouver le dernier fichier a analyser dt voici le rapport :

    Datei: winsp32.exe
    Auslastung:
    0% 100%
    Status:
    INFIZIERT/MALWARE (Anmerkung: diese Datei wurde bereits vorher gescannt. Die Scanergebnisse werden daher nicht in der Datenbank gespeichert.)
    Entdeckte Packprogramme:
    -
    Bit9 rapportiert: File not found

    A-Squared
    Keine Viren gefunden
    AntiVir
    Keine Viren gefunden
    ArcaVir
    Keine Viren gefunden
    Avast
    Win32:Googbot-B gefunden
    AVG Antivirus
    Keine Viren gefunden
    BitDefender
    Generic.Malware.GWX!.9DE9AF2F gefunden
    ClamAV
    Keine Viren gefunden
    CPsecure
    Keine Viren gefunden
    Dr.Web
    DLOADER.Trojan gefunden (mögliche Variante)
    F-Prot Antivirus
    Keine Viren gefunden
    F-Secure Anti-Virus
    Keine Viren gefunden
    Fortinet
    Keine Viren gefunden
    Ikarus
    Keine Viren gefunden
    Kaspersky Anti-Virus
    Keine Viren gefunden
    NOD32
    probably unknown NewHeur_PE gefunden (mögliche Variante)
    Norman Virus Control
    Keine Viren gefunden
    Panda Antivirus
    Keine Viren gefunden
    Rising Antivirus
    Keine Viren gefunden
    Sophos Antivirus
    Keine Viren gefunden
    VirusBuster
    Keine Viren gefunden
    VBA32
    Backdoor.xBot.1 (paranoid heuristics) gefunden (mögliche Variante)

    Sinon oui jai la version gratuite d'AVG

    Et voici le raport des 3 fichiers supprimer avec OTMoveIt :

    C:\WINDOWS\system32\hvukulap.exe moved successfully.
    C:\WINDOWS\system32\bsajxme.exe moved successfully.
    C:\WINDOWS\system32\snulfz.exe moved successfully.

    Created on 11/29/2007 20:25:39
    0
  3. g!rly Messages postés 18462 Statut Contributeur 407
     
    bon supprime celui aussi avec otmove it

    C:\WINDOWS\system32\winsp32.exe

    puis fais un scan en ligne ici :

    Scan en ligne bitdefender :

    https://www.bitdefender.com/toolbox/

    Clicker sur " I agree " et suivre les indications

    A faire imperativement sous internet explorer, en acceptant l´activ x

    tutoriel en image en image

    http://pageperso.aol.fr/rginformatique/mapage/defender.htm

    et post le rapport genere

    sinon je veux pas te saper le moral, mais antivir est beaucoup plus performant que avg

    regarde ceci pour comparer :

    http://www.matbe.com

    antivir

    https://www.malekal.com/avira-free-security-antivirus-gratuit/

    puis si tu decidait de changer il te faudrais aussi un par feu

    par feu : kerio

    https://www.vulgarisation-informatique.com/kerio.php

    @+
    0
  4. jackbenoit
     
    Pr ce qui est de Kerio ca y est je lai installer en debut d apres midi et je vai installer Antivir ce soir et voici mon rapport de bitdefender :

    Statistics

    Time

    01:32:23

    Files

    266998

    Folders

    6912

    Boot Sectors

    6

    Archives

    2124

    Packed Files

    9955

    Results

    Identified Viruses

    7

    Infected Files

    27

    Suspect Files

    1

    Warnings

    0

    Disinfected

    0

    Deleted Files

    30

    Engines Info

    Virus Definitions

    879486

    Engine build

    AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

    Scan plugins

    14

    Archive plugins

    38

    Unpack plugins

    7

    E-mail plugins

    6

    System plugins

    1

    Scan Settings

    First Action

    Disinfect

    Second Action

    Delete

    Heuristics

    Yes

    Enable Warnings

    Yes

    Scanned Extensions

    *;

    Exclude Extensions

    Scan Emails

    Yes

    Scan Archives

    Yes

    Scan Packed

    Yes

    Scan Files

    Yes

    Scan Boot

    Yes

    Scanned File

    Status

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil0920A210.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil0920A210.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil0920A210.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil0920A210.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil1B564529.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil1B564529.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil1B564529.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil1B564529.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil2CBB2E21.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil2CBB2E21.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil2CBB2E21.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil2CBB2E21.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil3ACB8490.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil3ACB8490.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil3ACB8490.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil3ACB8490.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil47D50840.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil47D50840.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil47D50840.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil47D50840.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil5A880BF9.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil5A880BF9.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil5A880BF9.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil5A880BF9.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil794CD7B1.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil794CD7B1.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil794CD7B1.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil794CD7B1.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil79EA1E61.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil79EA1E61.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil79EA1E61.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\fil79EA1E61.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filA0334AE4.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filA0334AE4.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filA0334AE4.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filA0334AE4.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filB7FFEF69.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filB7FFEF69.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filB7FFEF69.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filB7FFEF69.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filC0B23804.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filC0B23804.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filC0B23804.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filC0B23804.dat

    Updated

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filD1DE6424.dat=>(gzip)

    Infected with: Exploit.ADODB.Stream.BB

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filD1DE6424.dat=>(gzip)

    Disinfection failed

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filD1DE6424.dat=>(gzip)

    Deleted

    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filD1DE6424.dat

    Updated

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)=>(Instyler Module 2)=>(Quarantine-PE)

    Detected with: Application.VTesttool.A

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)=>(Instyler Module 2)=>(Quarantine-PE)

    Deleted

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)

    Update failed

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)=>(Instyler Module 3)=>(Quarantine-PE)

    Detected with: Application.VTesttool.B

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)=>(Instyler Module 3)=>(Quarantine-PE)

    Deleted

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)

    Update failed

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)=>(Instyler Module 4)=>(Quarantine-PE)

    Detected with: Application.VTesttool.C

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)=>(Instyler Module 4)=>(Quarantine-PE)

    Deleted

    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip=>setup.exe=>(Instyler o)

    Update failed

    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0020930.exe

    Suspected of: Generic.Malware.SCg.1396A8EE

    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0020930.exe

    Disinfection failed

    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0020930.exe

    Deleted

    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0027731.exe

    Infected with: Trojan.Dloader.AKO

    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0027731.exe

    Disinfection failed

    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0027731.exe

    Deleted

    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\repairRedist.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\repairRedist.htm

    Disinfection failed

    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\repairRedist.htm

    Deleted

    C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm

    Disinfection failed

    C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm

    Deleted

    C:\WINDOWS\system32\oobe\regerror\rnoansw.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\system32\oobe\regerror\rnoansw.htm

    Disinfection failed

    C:\WINDOWS\system32\oobe\regerror\rnoansw.htm

    Deleted

    C:\WINDOWS\system32\oobe\setup\drdymig.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\system32\oobe\setup\drdymig.htm

    Disinfection failed

    C:\WINDOWS\system32\oobe\setup\drdymig.htm

    Deleted

    C:\WINDOWS\system32\oobe\setup\drdyoem.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\system32\oobe\setup\drdyoem.htm

    Disinfection failed

    C:\WINDOWS\system32\oobe\setup\drdyoem.htm

    Deleted

    C:\WINDOWS\system32\oobe\setup\drdyref.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\system32\oobe\setup\drdyref.htm

    Disinfection failed

    C:\WINDOWS\system32\oobe\setup\drdyref.htm

    Deleted

    C:\WINDOWS\system32\oobe\setup\prodkey.htm

    Infected with: Trojan.Rahack.HTM

    C:\WINDOWS\system32\oobe\setup\prodkey.htm

    Disinfection failed

    C:\WINDOWS\system32\oobe\setup\prodkey.htm

    Deleted

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\bsajxme.exe

    Infected with: Generic.Malware.GWX!.9DE9AF2F

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\bsajxme.exe

    Disinfection failed

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\bsajxme.exe

    Deleted

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\hvukulap.exe

    Infected with: Generic.Malware.GWX!.9DE9AF2F

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\hvukulap.exe

    Disinfection failed

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\hvukulap.exe

    Deleted

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\snulfz.exe

    Infected with: Generic.Malware.GWX!.9DE9AF2F

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\snulfz.exe

    Disinfection failed

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\snulfz.exe

    Deleted

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\winsp32.exe

    Infected with: Generic.Malware.GWX!.9DE9AF2F

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\winsp32.exe

    Disinfection failed

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\winsp32.exe

    Delete failed
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. g!rly Messages postés 18462 Statut Contributeur 407
     
    salut jack benoit,

    la plus grande partie des infections visible ici etaient :

    dans la quarantaine soit de avg
    C:\Documents and Settings\Romain\Application Data\Grisoft\AVG Antispyware 7.5\quarantine\filC0B23804.dat=>(gzip)
    Deleted


    soit de ot_move it que l´on a utilisé plus haut :

    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\snulfz.exe
    Infected with: Generic.Malware.GWX!.9DE9AF2FC:\_OTMoveIt\MovedFiles\WINDOWS\system32\snulfz.exe
    Disinfection failed
    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\snulfz.exe
    Deleted


    il y a aussi ton test de securité
    C:\Documents and Settings\Romain\Mes documents\My Completed Downloads\pcsecuritytest.zip qui n´as pas plu a bitdefender

    pour le reste la restauration system est touché :
    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0027731.exe
    Infected with: Trojan.Dloader.AKO
    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0027731.exe
    Disinfection failed
    C:\System Volume Information\_restore{4C62093A-7D5F-4DEC-8CFD-50CC22E4923E}\RP58\A0027731.exe
    Deleted


    alors fais ceci pour assurer :

    Désactive ta restauration système:
    pour cela :
    Click droit sur poste de travail, dans l´arborescence sur propriétés;
    dans la nouvelle fenettre click sur l´onglet restauration système;
    coche la case désactiver la restauration systèm et applique.
    puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
    dans la nouvelle fenettre click sur l´onglet restauration systèm
    décoche la case désactiver la restauration systèm et applique.


    puis bitdefender a trouver ceci : des fichiers htlm infectés:

    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\repairRedist.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\repairRedist.htm
    Disinfection failed
    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\repairRedist.htm
    Deleted

    C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm
    Disinfection failed
    C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm
    Deleted

    C:\WINDOWS\system32\oobe\regerror\rnoansw.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\system32\oobe\regerror\rnoansw.htm
    Disinfection failed
    C:\WINDOWS\system32\oobe\regerror\rnoansw.htm
    Deleted

    C:\WINDOWS\system32\oobe\setup\drdymig.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\system32\oobe\setup\drdymig.htm
    Disinfection failed
    C:\WINDOWS\system32\oobe\setup\drdymig.htm
    Deleted

    C:\WINDOWS\system32\oobe\setup\drdyoem.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\system32\oobe\setup\drdyoem.htm
    Disinfection failed
    C:\WINDOWS\system32\oobe\setup\drdyoem.htm
    Deleted

    C:\WINDOWS\system32\oobe\setup\drdyref.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\system32\oobe\setup\drdyref.htm
    Disinfection failed
    C:\WINDOWS\system32\oobe\setup\drdyref.htm
    Deleted

    C:\WINDOWS\system32\oobe\setup\prodkey.htm
    Infected with: Trojan.Rahack.HTM
    C:\WINDOWS\system32\oobe\setup\prodkey.htm
    Disinfection failed
    C:\WINDOWS\system32\oobe\setup\prodkey.htm
    Deleted

    fais ceci :

    Télécharge Clean:

    -> http://www.malekal.com/download/clean.zip

    -> Dézippe tout le contenu dans un dossier que tu auras cré au préalable (sur ton bureau par exemple). Double clic sur clean ou clean.cmd choisie l'option 1.

    Un rapport va s'ouvrir, copie et colle le contenu sur le forum.

    -> pour ceux ou celles qui auraient un doute sur comment deziper un fichier :

    http://www.tutopat.com/viewtopic.php?t=933&sid=34215b238376bfb22ef9e8eca9995914

    @+
    0
Précédent
  • 1
  • 2