Virus bagle je crois - Page 2

Précédent
  • 1
  • 2
  1. dry
     
    Bonjour,
    oui je connais makehuman c'est un logiciel dont je me sers.
    Sinon j'ai mis antivir, c'est en train de scanner, après je mettrais zone alarm.
    Et là tu crois que ça sera bon?
    Est ce que tu pourras me dire comment enlever kaspersky et spybot aussi stp?
    merci beaucoup,
    dry
    0
  2. Utilisateur anonyme
     
    Re , pourquoi enlever spybot ?
    C'est un bon logiciel qui de plus possede un résident + scan passif ...
    Tiens moi au courant
    a+
    0
  3. dry
     
    parce qu'il fonctionne pas et j'arrive ni à l'enlever ni à le faire fonctionner, du coup je voulais l'enlever pour le reinstaller proprement...
    antivir m'a trouvé des virus qu'il a supprimé...
    0
  4. Utilisateur anonyme
     
    Re , tu as le rapport d'antivir stp ?

    ******************

    A+
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. dry
     
    je l'ai trouvé
    rapport antivir :

    AntiVir PersonalEdition Classic
    Report file date: jeudi 21 février 2008 09:24

    Scanning for 1118748 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows Vista
    Windows version: (plain) [6.0.6000]
    Username: France Designer inox
    Computer name: PC1

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 08:21:06
    ANTIVIR2.VDF : 7.0.2.113 1673728 Bytes 08/02/2008 08:21:06
    ANTIVIR3.VDF : 7.0.2.170 312832 Bytes 21/02/2008 08:21:06
    AVEWIN32.DLL : 7.6.0.67 3293696 Bytes 21/02/2008 08:21:06
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 21/02/2008 08:21:06
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Local Drives
    Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: J:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: jeudi 21 février 2008 09:24

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '0' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'VSSVC.exe' - '0' Module(s) have been scanned
    Scan process 'FlashUtil9d.exe' - '1' Module(s) have been scanned
    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
    Scan process 'ieuser.exe' - '1' Module(s) have been scanned
    Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
    Scan process 'BTStackServer.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
    Scan process 'CCU_Engine.exe' - '1' Module(s) have been scanned
    Scan process 'taskeng.exe' - '0' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'pmxmiced.exe' - '1' Module(s) have been scanned
    Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
    Scan process 'swBOEngine.exe' - '1' Module(s) have been scanned
    Scan process 'WiFiLB.exe' - '1' Module(s) have been scanned
    Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
    Scan process 'BTTray.exe' - '1' Module(s) have been scanned
    Scan process 'sprtcmd.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'PWRISOVM.EXE' - '1' Module(s) have been scanned
    Scan process 'IntelHCTAgent.exe' - '1' Module(s) have been scanned
    Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
    Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
    Scan process 'CCU_TrayIcon.exe' - '1' Module(s) have been scanned
    Scan process 'ico.exe' - '1' Module(s) have been scanned
    Scan process 'sttray.exe' - '1' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'dwm.exe' - '1' Module(s) have been scanned
    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
    Scan process 'mscorsvw.exe' - '0' Module(s) have been scanned
    Scan process 'WmiPrvSE.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'taskeng.exe' - '0' Module(s) have been scanned
    Scan process 'WUDFHost.exe' - '0' Module(s) have been scanned
    Scan process 'SearchIndexer.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'TrustedInstaller.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'stacsv.exe' - '0' Module(s) have been scanned
    Scan process 'sprtsvc.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'MDM.EXE' - '0' Module(s) have been scanned
    Scan process 'IAANTmon.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'DQLWinService.exe' - '0' Module(s) have been scanned
    Scan process 'btwdins.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'mDNSResponder.exe' - '0' Module(s) have been scanned
    Scan process 'AlertService.exe' - '0' Module(s) have been scanned
    Scan process 'PhotoshopElementsFileAgent.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '0' Module(s) have been scanned
    Scan process 'WUDFHost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'SLsvc.exe' - '0' Module(s) have been scanned
    Scan process 'audiodg.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'svchost.exe' - '0' Module(s) have been scanned
    Scan process 'lsm.exe' - '0' Module(s) have been scanned
    Scan process 'lsass.exe' - '0' Module(s) have been scanned
    Scan process 'services.exe' - '0' Module(s) have been scanned
    Scan process 'winlogon.exe' - '0' Module(s) have been scanned
    Scan process 'csrss.exe' - '0' Module(s) have been scanned
    Scan process 'wininit.exe' - '0' Module(s) have been scanned
    Scan process 'csrss.exe' - '0' Module(s) have been scanned
    Scan process 'smss.exe' - '0' Module(s) have been scanned
    32 processes with 32 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0005
    [NOTE] Please restart the search with Administrator rights
    Boot sector 'D:\'
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0005
    [NOTE] Please restart the search with Administrator rights
    Boot sector 'F:\'
    [NOTE] In the drive 'F:\' no data medium is inserted!
    Boot sector 'G:\'
    [NOTE] In the drive 'G:\' no data medium is inserted!
    Boot sector 'H:\'
    [NOTE] In the drive 'H:\' no data medium is inserted!
    Boot sector 'I:\'
    [NOTE] In the drive 'I:\' no data medium is inserted!

    Starting to scan the registry.
    The registry was scanned ( '28' files ).

    Starting the file scan:

    Begin scan in 'C:\' <OS>
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\QooBox\Quarantine\catchme2008-02-19_115152.50.zip
    [0] Archive type: ZIP
    --> srosa.sys
    [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> hldrrr.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Bagle.JW
    [INFO] The file was deleted!
    C:\QooBox\Quarantine\C\Windows\System32\drivers\hldrrr.exe.vir
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    C:\QooBox\Quarantine\C\Windows\System32\drivers\srosa.sys.vir
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    Begin scan in 'D:\' <RECOVERY>
    Begin scan in 'F:\'
    Search path F:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'G:\'
    Search path G:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'H:\'
    Search path H:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'I:\'
    Search path I:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'E:\'
    Search path E:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'J:\'
    Search path J:\ could not be opened!
    Le périphérique n'est pas prêt.

    End of the scan: jeudi 21 février 2008 10:02
    Used time: 37:23 min

    The scan has been done completely.

    21237 Scanning directories
    340696 Files were scanned
    4 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    3 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    2 Files cannot be scanned
    340692 Files not concerned
    1546 Archives were scanned
    2 Warnings
    0 Notes

    merci encore...
    0
  7. Utilisateur anonyme
     
    Re , ok il a trouvé le bagle qui était dans la quarantaine de Combofix -> Pas de soucis ;)

    ***************

    HijackThis -> Open the misc tools sections -> open Uninstall manager -> clique sur "Save list" -> Enregistre le fichier -> fais-en un copier/coller ici.

    A+
    0
  8. Utilisateur anonyme
     
    Re ,
    Je disais Antivir a trouvé les virus que Combofix avait supprimés ( mis en quarantaines , donc pas de soucis de ce coté la )

    Lance HijackThis -> Open the misc tools sections -> open Uninstall manager -> clique sur "Save list" -> Enregistre le fichier -> fais-en un copier/coller ici.

    A+
    0
  9. dry
     
    voilà :
    32 Bit HP CIO Components Installer
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Common File Installer
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe ExtendScript Toolkit 2
    Adobe Flash Player ActiveX
    Adobe Help Viewer CS3
    Adobe Illustrator CS
    Adobe InDesign CS
    Adobe PDF Library Files
    Adobe Photoshop CS
    Adobe Photoshop Elements 6.0
    Adobe Premiere Elements 4.0
    Adobe Premiere Elements 4.0
    Adobe Premiere Elements 4.0 Templates
    Adobe Premiere Elements 4.0 Templates
    Adobe Reader 8.1.0 - Français
    Adobe Setup
    Adobe Soundbooth CS3
    Adobe Soundbooth CS3
    Adobe Soundbooth CS3 Codecs
    Adobe Soundbooth CS3 Scores
    Adobe SVG Viewer 3.0
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe XMP DVA Panels CS3
    Adobe XMP Panels CS3
    Avira AntiVir PersonalEdition Classic
    Blender (remove only)
    Browser Address Error Redirector
    Dell Support Center
    EPSON Printer Software
    Google Desktop
    Guide de l'utilisateur
    Hercules WiFi Station for Livebox
    HijackThis 2.0.2
    HP Customer Participation Program 8.0
    HP Imaging Device Functions 8.0
    HP OCR Software 8.0
    HP Officejet Pro All-In-One Series
    HP Photosmart Essential
    HP Solution Center 8.0
    HP Update
    HPSSupply
    Intel(R) Matrix Storage Manager
    Intel(R) PRO Network Connections 12.1.12.4
    Intel(R) PRO Network Connections 12.1.12.4
    Intel(R) PRO Network Connections Drivers
    Java(TM) SE Runtime Environment 6
    Logiciel Intel® Viiv™
    Microsoft Office 2003 Web Components
    Microsoft Office Standard Edition 2003
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mouse Suite for Desktop Computers
    MPM
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    NVIDIA Drivers
    Orange Preload
    PowerISO
    Roxio Activation Module
    Roxio Creator Audio
    Roxio Creator BDAV Plugin
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator Premier
    Roxio Creator Tools
    Roxio EasyArchive
    Roxio Express Labeler
    Roxio MyDVD Premier
    Roxio Update Manager
    SolidWorks 2008 SP0
    Sonic CinePlayer Decoder Pack
    WIDCOMM Bluetooth Software 6.0.1.4300

    c bon????
    0
  10. Utilisateur anonyme
     
    Re ,

    Pour Spybot , va dans C:\programme\spybot search&destroy <-- Vire le dossier en MSE

    Fait de même pour Kaspersky qui doit se situer dans C:\programme\

    Voila tiens moi au courant des difficultées rencontrées , je part pour l'aprem ;)
    A+
    0
  11. dry
     
    je trouve pas de fichier en MSE, et je trouve meme pas spybot dans programme...
    bonne aprem
    dry
    0
  12. Utilisateur anonyme
     
    Re , il n'y sont plus alors =)

    ******************

    Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

    # Double clique sur ToolsCleaner2.exe >
    # Clique sur .Recherche
    # puis sur Suppression quand la liste est trouvée.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
    # Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

    CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
    Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

    Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

    Tuto : http://www.commentcamarche.net/faq/sujet 8341 toolscleaner suppression des fix de force brute ( merci espion3004 )
    A+

    0
Précédent
  • 1
  • 2