Lien photo MSN

Résolu
Big Or No -  
g!rly Messages postés 18215 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour
j'ai moi aussi eu la mauvaise idée d'ouvrir ce lien a la c**.
Tout d'abord merci pour le forum j'ai peu telecharger le lien et suivre vos instructions.
Je vous copie/colle mon report.txt.

Au faite quelles peuvent les conséquences de ce virus?

Merci

JUL


[b]SDFix: Version 1.153 /b

Run by Vincent on 06/03/2008 at 17:14

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services /b:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


[b]Checking Files /b:

Trojan Files Found:

C:\SALXLS~1.EXE - Deleted
C:\WINDOWS\mrofinu1423.exe - Deleted
C:\DOCUME~1\Vincent\LOCALS~1\Temp\services.exe - Deleted
C:\autorun.inf - Deleted





Removing Temp Files

[b]ADS Check /b:



[b]Final Check /b:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 17:22:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\­Components\\x90\x2022\x20ac|\xff\xff\xff\xff"\x2022\x20ac|\xf9\x2022\xd1w\2]
"91A14B995DF7C0B42ABAA16065968F3A"="C:\Program Files\Alias\Maya7.0\presets\Ashli\"

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services /b:



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpoli­cy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enable­d:@xpsp2res.dll,-22019"
"C:\\Program Files\\Alias\\Maya 6.0 Personal Learning Edition\\bin\\maya.exe"="C:\\Program Files\\Alias\\Maya 6.0 Personal Learning Edition\\bin\\maya.exe:*:Enabled:Maya"
"C:\\Program Files\\FlexiSIGN 7.6v2\\Program\\App.exe"="C:\\Program Files\\FlexiSIGN 7.6v2\\Program\\App.exe:*:Enabled:Design Software"
"C:\\Program Files\\FlexiSIGN 7.6v2\\Program\\App2.exe"="C:\\Program Files\\FlexiSIGN 7.6v2\\Program\\App2.exe:*:Enabled:Production"
"C:\\Program Files\\Dantz\\Client\\retroclient.exe"="C:\\Program Files\\Dantz\\Client\\retroclient.exe:*:Enabled:Retrospect Client"
"C:\\Program Files\\Timbuktu Pro\\tb2pro.exe"="C:\\Program Files\\Timbuktu Pro\\tb2pro.exe:*:Enabled:Timbuktu Pro"
"C:\\Program Files\\Timbuktu Pro\\MiniTB2.exe"="C:\\Program Files\\Timbuktu Pro\\MiniTB2.exe:*:Enabled:MiniTB2"
"C:\\Program Files\\Timbuktu Pro\\TB2Scan.exe"="C:\\Program Files\\Timbuktu Pro\\TB2Scan.exe:*:Enabled:Timbuktu Pro Scanner"
"C:\\aflaser\\laserdesign\\air\\bin\\airshow.exe"="C:\\aflaser\\laserdesign­\\air\\bin\\airshow.exe:*:Enabled:airshow"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\DOCUME~1\\Vincent\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\Vincen­t\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpoli­cy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enable­d:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[b]Remaining Files /b:


File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes /b:

Thu 24 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\585dc2612ebcefc90e7dee4c276ee95e\BIT4.tmp&q­uot;

[b]Finished!/b
A voir également:

21 réponses

g!rly Messages postés 18215 Date d'inscription   Statut Contributeur Dernière intervention   406
 
ok tres bien ;)
0