Désinfection du virus"ta photo sur ce site&qu

clubber-62 -  
clubber-62 Messages postés 47 Statut Membre -
Bonjour,

j'ai chopé le même virus "quet-ce que ta photo fait sur ce site"si qu'elqu'un de sérieux pouvais m'aider a m'en débarasser une fois pour de bon se ne saurais pas de refus!

g télécharger c-cleaner, spybot, avast et hijackthis

symptomes:
mon ordi redémare une fois l'orsque je souhaite l'éteindre , avast m'in dique que je suis infecté, l'orsque je lance le scan avast il n'arrive pas à réparer ou mettre en quarantaine 3 fichiers win.32 et windows m'indique que mon ordi court un risque car aucun pare feu n'est activé alors qu'il l'est quand je vé dans panneau de config

qu'elqu'un pour me venir en aide ?

merci d'avance pour vos réponses
Configuration: Windows XP
Internet Explorer 6.0

2 réponses

  1. clubber-62
     
    tout d'abord je viens de faire un scan avec spybot et il me trouve ces 3 éléments:

    MailSkinner.rtk (fichier texte)
    c:windows/temp/msk/setup.log

    Win32.tini.abk (2éléments)
    c:windows/temp/AE8AB41F9F72503.tmp
    c:windows/temp/7CF28762C38CA0D4;tmp
    0
    1. clubber-62 Messages postés 47 Statut Membre
       
      ensuite voici le scan par bitdefender en ligne:

      BitDefender Online Scanner



      Scan report generated at: Sat, Mar 08, 2008 - 20:16:19





      Scan path: A:\;C:\;D:\;E:\;G:\;







      Statistics

      Time
      01:59:04

      Files
      207365

      Folders
      6556

      Boot Sectors
      4

      Archives
      1865

      Packed Files
      13875




      Results

      Identified Viruses
      32

      Infected Files
      75

      Suspect Files
      0

      Warnings
      0

      Disinfected
      0

      Deleted Files
      73




      Engines Info

      Virus Definitions
      986189

      Engine build
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Scan plugins
      16

      Archive plugins
      41

      Unpack plugins
      7

      E-mail plugins
      6

      System plugins
      5




      Scan Settings

      First Action
      Disinfect

      Second Action
      Delete

      Heuristics
      Yes

      Enable Warnings
      Yes

      Scanned Extensions
      *;

      Exclude Extensions


      Scan Emails
      Yes

      Scan Archives
      Yes

      Scan Packed
      Yes

      Scan Files
      Yes

      Scan Boot
      Yes




      Scanned File
      Status

      C:\Documents and Settings\-\egaict.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\-\egaict.exe
      Disinfection failed

      C:\Documents and Settings\-\egaict.exe
      Deleted

      C:\Documents and Settings\-\phgljd.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\-\phgljd.exe
      Disinfection failed

      C:\Documents and Settings\-\phgljd.exe
      Deleted

      C:\Documents and Settings\-\pmrknn.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\-\pmrknn.exe
      Disinfection failed

      C:\Documents and Settings\-\pmrknn.exe
      Deleted

      C:\Documents and Settings\-\rmeuxc.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\-\rmeuxc.exe
      Disinfection failed

      C:\Documents and Settings\-\rmeuxc.exe
      Deleted

      C:\Documents and Settings\-\yesvsi.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\-\yesvsi.exe
      Disinfection failed

      C:\Documents and Settings\-\yesvsi.exe
      Deleted

      C:\Documents and Settings\julien\Application Data\HbTools\v3.0\HbTools\static\1\country.exe
      Detected with: Adware.Hotbar.CB

      C:\Documents and Settings\julien\Application Data\HbTools\v3.0\HbTools\static\1\country.exe
      Deleted

      C:\Documents and Settings\julien\evygqa.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\julien\evygqa.exe
      Disinfection failed

      C:\Documents and Settings\julien\evygqa.exe
      Deleted

      C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
      Disinfection failed

      C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
      Deleted

      C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
      Disinfection failed

      C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
      Deleted

      C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
      Detected with: Application.Powerreg.Scheduler.C

      C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
      Disinfection failed

      C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
      Deleted

      C:\Documents and Settings\julien\mzjztt.exe
      Infected with: Trojan.Retapu.D

      C:\Documents and Settings\julien\mzjztt.exe
      Disinfection failed

      C:\Documents and Settings\julien\mzjztt.exe
      Deleted

      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
      Infected with: Trojan.Downloader.Zlob.ABMO

      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
      Disinfection failed

      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
      Deleted

      C:\Program Files\Helper\1204228948.dll
      Infected with: Trojan.Downloader.Zlob.ABMP

      C:\Program Files\Helper\1204228948.dll
      Disinfection failed

      C:\Program Files\Helper\1204228948.dll
      Delete failed

      C:\Program Files\NetProject\sbmdl.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\Program Files\NetProject\sbmdl.dll
      Disinfection failed

      C:\Program Files\NetProject\sbmdl.dll
      Delete failed

      C:\Program Files\NetProject\sbmntr.exe
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\Program Files\NetProject\sbmntr.exe
      Disinfection failed

      C:\Program Files\NetProject\sbmntr.exe
      Deleted

      C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
      Infected with: Trojan.Downloader.Zlob.ABMT

      C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
      Disinfection failed

      C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
      Deleted

      C:\Program Files\NetProject\uninst.exe=>(NSIS o)
      Update failed

      C:\Program Files\NetProject\waun.exe
      Infected with: MemScan:Trojan.Downloader.Zlob.ABNI

      C:\Program Files\NetProject\waun.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
      Detected with: Adware.Navipromo.BZL

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211370.DLL
      Detected with: Adware.Mywebsearch.AQ

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211370.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211372.DLL
      Detected with: Adware.Mywebsearch.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211372.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211374.DLL
      Detected with: Adware.Mywebsearch.AL

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211374.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211377.DLL
      Infected with: Trojan.Funweb.A

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211377.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
      Detected with: Application.MWS

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211379.DLL
      Detected with: Adware.Mywebsearch.AF

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211379.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211383.EXE
      Detected with: Adware.Msearch.P

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211383.EXE
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211387.DLL
      Detected with: Adware.Mywebsearch.F

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211387.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211393.EXE
      Detected with: Adware.Mywebsearch.I

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211393.EXE
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211394.DLL
      Detected with: Adware.Mywebsearch.Q

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211394.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211395.DLL
      Detected with: Adware.Toolbar.MyWebSearch.AC

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211395.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211396.DLL
      Detected with: Adware.Mywebsearch.C

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211396.DLL
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211397.exe
      Detected with: Adware.SpywareSecure.B

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211397.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
      Infected with: Backdoor.IRCBot.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221715.exe
      Infected with: Trojan.Srizbi.BF

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221715.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221716.exe
      Infected with: Backdoor.Rustock.NCI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221716.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
      Infected with: Trojan.DNSChanger.BX

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
      Infected with: Trojan.DNSChanger.BX

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221720.exe
      Infected with: Trojan.Agent.AHEI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221720.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221724.exe
      Infected with: Trojan.Downloader.JJPL

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221724.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
      Infected with: Trojan.Downloader.Zlob.ABMP

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224856.exe
      Infected with: Trojan.Downloader.JJPL

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224856.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224857.exe
      Infected with: Trojan.Downloader.JJPL

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224857.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224858.dll
      Infected with: Trojan.Downloader.Agent.BJI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224858.dll
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP947\A0232298.exe
      Infected with: Trojan.Downloader.JJPT

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP947\A0232298.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239409.exe
      Detected with: Adware.Hotbar.CB

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239409.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
      Detected with: Application.Powerreg.Scheduler.C

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
      Infected with: Trojan.Retapu.D

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
      Infected with: Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
      Disinfection failed

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
      Deleted

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239414.exe
      Infected with: MemScan:Trojan.Downloader.Zlob.ABNI

      C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239414.exe
      Deleted

      C:\WINDOWS\Downloaded Program Files\AxInst.exe
      Infected with: Trojan.Dropper.CP

      C:\WINDOWS\Downloaded Program Files\AxInst.exe
      Deleted

      C:\WINDOWS\Downloaded Program Files\UWAS6V_0001_N68M1103NetInstaller.exe
      Infected with: Trojan.Downloader.RW

      C:\WINDOWS\Downloaded Program Files\UWAS6V_0001_N68M1103NetInstaller.exe
      Deleted

      C:\WINDOWS\system32\jdqhnl.exe
      Infected with: Trojan.Retapu.D

      C:\WINDOWS\system32\jdqhnl.exe
      Disinfection failed

      C:\WINDOWS\system32\jdqhnl.exe
      Deleted

      C:\WINDOWS\system32\mykmpt.exe
      Infected with: Trojan.Retapu.D

      C:\WINDOWS\system32\mykmpt.exe
      Disinfection failed

      C:\WINDOWS\system32\mykmpt.exe
      Deleted

      C:\WINDOWS\system32\nazvot.exe
      Infected with: Trojan.Retapu.D

      C:\WINDOWS\system32\nazvot.exe
      Disinfection failed

      C:\WINDOWS\system32\nazvot.exe
      Deleted
      0
      1. clubber-62 Messages postés 47 Statut Membre > clubber-62 Messages postés 47 Statut Membre
         
        enfin voici le log hijackthis :

        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
        Scan saved at 02:51:46, on 09/03/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\System32\LVCOMSX.EXE
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\drivers\KodakCCS.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        C:\WINDOWS\System32\UAService7.exe
        C:\Program Files\Logitech\Video\FxSvr2.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Documents and Settings\-\Mes documents\logiciel\HiJackThis_v2.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\-\LOCALS~1\Temp\services.exe
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: e404 helper - {C03FD59D-9104-44B7-929A-9EAA0BA05211} - C:\Program Files\Helper\1204228948.dll
        O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll
        O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\-\LOCALS~1\Temp\services.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\DOCUME~1\-\LOCALS~1\Temp\E_SC.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
        O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
        O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: &Search - ?p=ZRxdm185YYFR
        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.browsergate.com/redirect.php (file missing)
        O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.browsergate.com/redirect.php (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
        O16 - DPF: {2472DCCC-68CE-49DA-AA81-E7E6D83C1DFA} - http://acces.blonde.com/package/PackageHtmlCab.CAB
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
        O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://mmt.bouyguestelecom.fr/mmawap/jsp/composer/player/mmsPlayer.cab
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
        O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f004.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
        O16 - DPF: {E68718BB-5451-4F6F-B8B8-41B4AB672747} (IgbInstall Class) - http://www.internetgamebox.com/content/AxInst.cab
        O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
        O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
        O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
        O22 - SharedTaskScheduler: corduroyed - {699fabf8-1087-491f-b57c-80a68929d82b} - (no file)
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
        O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
        O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
        O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
        O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe
        O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
        0
  2. clubber-62 Messages postés 47 Statut Membre
     
    quelqu'un pourais me venir en aide svp?
    0