Virus ta photo sur ce site: log et scan
Résolu
clubber-62
Messages postés
47
Statut
Membre
-
clubber-62 Messages postés 47 Statut Membre -
clubber-62 Messages postés 47 Statut Membre -
Bonjour,
j'ai chopé le virus "quest-ce que ta photo fait sur ce site"si qu'elqu'un de sérieux pouvais m'aider a m'en débarasser une fois pour de bon se ne saurais pas de refus!
g télécharger c-cleaner, spybot, avast et hijackthis
symptomes:
mon ordi redémare une fois l'orsque je souhaite l'éteindre , avast m'in dique que je suis infecté, l'orsque je lance le scan avast il n'arrive pas à réparer ou mettre en quarantaine 3 fichiers win.32 et windows m'indique que mon ordi court un risque car aucun pare feu n'est activé alors qu'il l'est quand je vé dans panneau de config
qu'elqu'un pour me venir en aide ?
merci d'avance pour vos réponses
Configuration: Windows XP
tout d'abord je viens de faire un scan avec spybot et il me trouve ces 3 éléments:
MailSkinner.rtk (fichier texte)
c:windows/temp/msk/setup.log
Win32.tini.abk (2éléments)
c:windows/temp/AE8AB41F9F72503.tmp
c:windows/temp/7CF28762C38CA0D4;tmp
puis le scan en ligne avec bitdefender:
BitDefender Online Scanner
Scan report generated at: Sat, Mar 08, 2008 - 20:16:19
Scan path: A:\;C:\;D:\;E:\;G:\;
Statistics
Time
01:59:04
Files
207365
Folders
6556
Boot Sectors
4
Archives
1865
Packed Files
13875
Results
Identified Viruses
32
Infected Files
75
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
73
Engines Info
Virus Definitions
986189
Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)
Scan plugins
16
Archive plugins
41
Unpack plugins
7
E-mail plugins
6
System plugins
5
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\-\egaict.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\egaict.exe
Disinfection failed
C:\Documents and Settings\-\egaict.exe
Deleted
C:\Documents and Settings\-\phgljd.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\phgljd.exe
Disinfection failed
C:\Documents and Settings\-\phgljd.exe
Deleted
C:\Documents and Settings\-\pmrknn.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\pmrknn.exe
Disinfection failed
C:\Documents and Settings\-\pmrknn.exe
Deleted
C:\Documents and Settings\-\rmeuxc.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\rmeuxc.exe
Disinfection failed
C:\Documents and Settings\-\rmeuxc.exe
Deleted
C:\Documents and Settings\-\yesvsi.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\yesvsi.exe
Disinfection failed
C:\Documents and Settings\-\yesvsi.exe
Deleted
C:\Documents and Settings\julien\Application Data\HbTools\v3.0\HbTools\static\1\country.exe
Detected with: Adware.Hotbar.CB
C:\Documents and Settings\julien\Application Data\HbTools\v3.0\HbTools\static\1\country.exe
Deleted
C:\Documents and Settings\julien\evygqa.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\evygqa.exe
Disinfection failed
C:\Documents and Settings\julien\evygqa.exe
Deleted
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
Disinfection failed
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
Deleted
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
Disinfection failed
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
Deleted
C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
Detected with: Application.Powerreg.Scheduler.C
C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
Disinfection failed
C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
Deleted
C:\Documents and Settings\julien\mzjztt.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\mzjztt.exe
Disinfection failed
C:\Documents and Settings\julien\mzjztt.exe
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
Infected with: Trojan.Downloader.Zlob.ABMO
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
Deleted
C:\Program Files\Helper\1204228948.dll
Infected with: Trojan.Downloader.Zlob.ABMP
C:\Program Files\Helper\1204228948.dll
Disinfection failed
C:\Program Files\Helper\1204228948.dll
Delete failed
C:\Program Files\NetProject\sbmdl.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\Program Files\NetProject\sbmdl.dll
Disinfection failed
C:\Program Files\NetProject\sbmdl.dll
Delete failed
C:\Program Files\NetProject\sbmntr.exe
Infected with: Trojan.Downloader.Zlob.ABNI
C:\Program Files\NetProject\sbmntr.exe
Disinfection failed
C:\Program Files\NetProject\sbmntr.exe
Deleted
C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
Infected with: Trojan.Downloader.Zlob.ABMT
C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
Disinfection failed
C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
Deleted
C:\Program Files\NetProject\uninst.exe=>(NSIS o)
Update failed
C:\Program Files\NetProject\waun.exe
Infected with: MemScan:Trojan.Downloader.Zlob.ABNI
C:\Program Files\NetProject\waun.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
Detected with: Adware.Navipromo.BZL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211370.DLL
Detected with: Adware.Mywebsearch.AQ
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211370.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211372.DLL
Detected with: Adware.Mywebsearch.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211372.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211374.DLL
Detected with: Adware.Mywebsearch.AL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211374.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211377.DLL
Infected with: Trojan.Funweb.A
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211377.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
Detected with: Application.MWS
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211379.DLL
Detected with: Adware.Mywebsearch.AF
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211379.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211383.EXE
Detected with: Adware.Msearch.P
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211383.EXE
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211387.DLL
Detected with: Adware.Mywebsearch.F
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211387.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211393.EXE
Detected with: Adware.Mywebsearch.I
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211393.EXE
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211394.DLL
Detected with: Adware.Mywebsearch.Q
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211394.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211395.DLL
Detected with: Adware.Toolbar.MyWebSearch.AC
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211395.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211396.DLL
Detected with: Adware.Mywebsearch.C
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211396.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211397.exe
Detected with: Adware.SpywareSecure.B
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211397.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
Infected with: Backdoor.IRCBot.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221715.exe
Infected with: Trojan.Srizbi.BF
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221715.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221716.exe
Infected with: Backdoor.Rustock.NCI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221716.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
Infected with: Trojan.DNSChanger.BX
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
Infected with: Trojan.DNSChanger.BX
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221720.exe
Infected with: Trojan.Agent.AHEI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221720.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221724.exe
Infected with: Trojan.Downloader.JJPL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221724.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
Infected with: Trojan.Downloader.Zlob.ABMP
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224856.exe
Infected with: Trojan.Downloader.JJPL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224856.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224857.exe
Infected with: Trojan.Downloader.JJPL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224857.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224858.dll
Infected with: Trojan.Downloader.Agent.BJI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224858.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP947\A0232298.exe
Infected with: Trojan.Downloader.JJPT
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP947\A0232298.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239409.exe
Detected with: Adware.Hotbar.CB
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239409.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
Detected with: Application.Powerreg.Scheduler.C
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239414.exe
Infected with: MemScan:Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239414.exe
Deleted
C:\WINDOWS\Downloaded Program Files\AxInst.exe
Infected with: Trojan.Dropper.CP
C:\WINDOWS\Downloaded Program Files\AxInst.exe
Deleted
C:\WINDOWS\Downloaded Program Files\UWAS6V_0001_N68M1103NetInstaller.exe
Infected with: Trojan.Downloader.RW
C:\WINDOWS\Downloaded Program Files\UWAS6V_0001_N68M1103NetInstaller.exe
Deleted
C:\WINDOWS\system32\jdqhnl.exe
Infected with: Trojan.Retapu.D
C:\WINDOWS\system32\jdqhnl.exe
Disinfection failed
C:\WINDOWS\system32\jdqhnl.exe
Deleted
C:\WINDOWS\system32\mykmpt.exe
Infected with: Trojan.Retapu.D
C:\WINDOWS\system32\mykmpt.exe
Disinfection failed
C:\WINDOWS\system32\mykmpt.exe
Deleted
C:\WINDOWS\system32\nazvot.exe
Infected with: Trojan.Retapu.D
C:\WINDOWS\system32\nazvot.exe
Disinfection failed
C:\WINDOWS\system32\nazvot.exe
Deleted'+String.fromCharCode(60)+'b'+String.fromCharCode(62)+'4'+String.fromCharCode(60)+'/b'+String.fromCharCode(62)+' message(s) posté(s) depuis le '+String.fromCharCode(60)+'b'+String.fromCharCode(62)+'samedi 8 mars 2008'+String.fromCharCode(60)+'/b'+String.fromCharCode(62)+'
Puis voici le log de hijackthis:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 02:51:46, on 09/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\-\Mes documents\logiciel\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\-\LOCALS~1\Temp\services.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: e404 helper - {C03FD59D-9104-44B7-929A-9EAA0BA05211} - C:\Program Files\Helper\1204228948.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\-\LOCALS~1\Temp\services.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\DOCUME~1\-\LOCALS~1\Temp\E_SC.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - ?p=ZRxdm185YYFR
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.browsergate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.browsergate.com/redirect.php (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {2472DCCC-68CE-49DA-AA81-E7E6D83C1DFA} - http://acces.blonde.com/package/PackageHtmlCab.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://mmt.bouyguestelecom.fr/mmawap/jsp/composer/player/mmsPlayer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f004.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
O16 - DPF: {E68718BB-5451-4F6F-B8B8-41B4AB672747} (IgbInstall Class) - http://www.internetgamebox.com/content/AxInst.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: corduroyed - {699fabf8-1087-491f-b57c-80a68929d82b} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
Quelqu'un peut-il me venir en aide SVP?????
je n'y comprend pas grand chose a ces annalyses de ces différents logiciels !!!!
Aidez moi SVP
j'ai chopé le virus "quest-ce que ta photo fait sur ce site"si qu'elqu'un de sérieux pouvais m'aider a m'en débarasser une fois pour de bon se ne saurais pas de refus!
g télécharger c-cleaner, spybot, avast et hijackthis
symptomes:
mon ordi redémare une fois l'orsque je souhaite l'éteindre , avast m'in dique que je suis infecté, l'orsque je lance le scan avast il n'arrive pas à réparer ou mettre en quarantaine 3 fichiers win.32 et windows m'indique que mon ordi court un risque car aucun pare feu n'est activé alors qu'il l'est quand je vé dans panneau de config
qu'elqu'un pour me venir en aide ?
merci d'avance pour vos réponses
Configuration: Windows XP
tout d'abord je viens de faire un scan avec spybot et il me trouve ces 3 éléments:
MailSkinner.rtk (fichier texte)
c:windows/temp/msk/setup.log
Win32.tini.abk (2éléments)
c:windows/temp/AE8AB41F9F72503.tmp
c:windows/temp/7CF28762C38CA0D4;tmp
puis le scan en ligne avec bitdefender:
BitDefender Online Scanner
Scan report generated at: Sat, Mar 08, 2008 - 20:16:19
Scan path: A:\;C:\;D:\;E:\;G:\;
Statistics
Time
01:59:04
Files
207365
Folders
6556
Boot Sectors
4
Archives
1865
Packed Files
13875
Results
Identified Viruses
32
Infected Files
75
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
73
Engines Info
Virus Definitions
986189
Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)
Scan plugins
16
Archive plugins
41
Unpack plugins
7
E-mail plugins
6
System plugins
5
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\-\egaict.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\egaict.exe
Disinfection failed
C:\Documents and Settings\-\egaict.exe
Deleted
C:\Documents and Settings\-\phgljd.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\phgljd.exe
Disinfection failed
C:\Documents and Settings\-\phgljd.exe
Deleted
C:\Documents and Settings\-\pmrknn.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\pmrknn.exe
Disinfection failed
C:\Documents and Settings\-\pmrknn.exe
Deleted
C:\Documents and Settings\-\rmeuxc.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\rmeuxc.exe
Disinfection failed
C:\Documents and Settings\-\rmeuxc.exe
Deleted
C:\Documents and Settings\-\yesvsi.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\-\yesvsi.exe
Disinfection failed
C:\Documents and Settings\-\yesvsi.exe
Deleted
C:\Documents and Settings\julien\Application Data\HbTools\v3.0\HbTools\static\1\country.exe
Detected with: Adware.Hotbar.CB
C:\Documents and Settings\julien\Application Data\HbTools\v3.0\HbTools\static\1\country.exe
Deleted
C:\Documents and Settings\julien\evygqa.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\evygqa.exe
Disinfection failed
C:\Documents and Settings\julien\evygqa.exe
Deleted
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
Disinfection failed
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\FW4DLB8T\addz[1].exe
Deleted
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
Disinfection failed
C:\Documents and Settings\julien\Local Settings\Temporary Internet Files\Content.IE5\RG4M86ZC\addz[1].exe
Deleted
C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
Detected with: Application.Powerreg.Scheduler.C
C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
Disinfection failed
C:\Documents and Settings\julien\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler.exe
Deleted
C:\Documents and Settings\julien\mzjztt.exe
Infected with: Trojan.Retapu.D
C:\Documents and Settings\julien\mzjztt.exe
Disinfection failed
C:\Documents and Settings\julien\mzjztt.exe
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
Infected with: Trojan.Downloader.Zlob.ABMO
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1B5XKKFH\sdferw[1].htm
Deleted
C:\Program Files\Helper\1204228948.dll
Infected with: Trojan.Downloader.Zlob.ABMP
C:\Program Files\Helper\1204228948.dll
Disinfection failed
C:\Program Files\Helper\1204228948.dll
Delete failed
C:\Program Files\NetProject\sbmdl.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\Program Files\NetProject\sbmdl.dll
Disinfection failed
C:\Program Files\NetProject\sbmdl.dll
Delete failed
C:\Program Files\NetProject\sbmntr.exe
Infected with: Trojan.Downloader.Zlob.ABNI
C:\Program Files\NetProject\sbmntr.exe
Disinfection failed
C:\Program Files\NetProject\sbmntr.exe
Deleted
C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
Infected with: Trojan.Downloader.Zlob.ABMT
C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
Disinfection failed
C:\Program Files\NetProject\uninst.exe=>(NSIS o)=>lzma_nsis0000
Deleted
C:\Program Files\NetProject\uninst.exe=>(NSIS o)
Update failed
C:\Program Files\NetProject\waun.exe
Infected with: MemScan:Trojan.Downloader.Zlob.ABNI
C:\Program Files\NetProject\waun.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
Detected with: Adware.Navipromo.BZL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP837\A0211190.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211370.DLL
Detected with: Adware.Mywebsearch.AQ
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211370.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211372.DLL
Detected with: Adware.Mywebsearch.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211372.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211374.DLL
Detected with: Adware.Mywebsearch.AL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211374.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211377.DLL
Infected with: Trojan.Funweb.A
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211377.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
Detected with: Application.MWS
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211378.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211379.DLL
Detected with: Adware.Mywebsearch.AF
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211379.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211383.EXE
Detected with: Adware.Msearch.P
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211383.EXE
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211387.DLL
Detected with: Adware.Mywebsearch.F
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211387.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211393.EXE
Detected with: Adware.Mywebsearch.I
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211393.EXE
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211394.DLL
Detected with: Adware.Mywebsearch.Q
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211394.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211395.DLL
Detected with: Adware.Toolbar.MyWebSearch.AC
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211395.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211396.DLL
Detected with: Adware.Mywebsearch.C
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211396.DLL
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211397.exe
Detected with: Adware.SpywareSecure.B
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP840\A0211397.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
Infected with: Backdoor.IRCBot.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221684.com
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221696.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221714.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221715.exe
Infected with: Trojan.Srizbi.BF
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221715.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221716.exe
Infected with: Backdoor.Rustock.NCI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221716.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
Infected with: Trojan.DNSChanger.BX
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221717.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
Infected with: Trojan.DNSChanger.BX
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221719.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221720.exe
Infected with: Trojan.Agent.AHEI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221720.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221724.exe
Infected with: Trojan.Downloader.JJPL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221724.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221773.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0221787.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0222787.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0223790.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224790.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP940\A0224812.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224837.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
Infected with: Trojan.Downloader.Zlob.ABMP
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224855.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224856.exe
Infected with: Trojan.Downloader.JJPL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224856.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224857.exe
Infected with: Trojan.Downloader.JJPL
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224857.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224858.dll
Infected with: Trojan.Downloader.Agent.BJI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP941\A0224858.dll
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0226238.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227240.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP945\A0227242.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP947\A0232298.exe
Infected with: Trojan.Downloader.JJPT
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP947\A0232298.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239383.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239384.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239385.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239386.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239404.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239405.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239406.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239407.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239408.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239409.exe
Detected with: Adware.Hotbar.CB
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239409.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239410.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
Detected with: Application.Powerreg.Scheduler.C
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239411.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
Infected with: Trojan.Retapu.D
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239412.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
Infected with: Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
Disinfection failed
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239413.exe
Deleted
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239414.exe
Infected with: MemScan:Trojan.Downloader.Zlob.ABNI
C:\System Volume Information\_restore{ECE47022-B9E1-4222-BDED-F58B23E67443}\RP950\A0239414.exe
Deleted
C:\WINDOWS\Downloaded Program Files\AxInst.exe
Infected with: Trojan.Dropper.CP
C:\WINDOWS\Downloaded Program Files\AxInst.exe
Deleted
C:\WINDOWS\Downloaded Program Files\UWAS6V_0001_N68M1103NetInstaller.exe
Infected with: Trojan.Downloader.RW
C:\WINDOWS\Downloaded Program Files\UWAS6V_0001_N68M1103NetInstaller.exe
Deleted
C:\WINDOWS\system32\jdqhnl.exe
Infected with: Trojan.Retapu.D
C:\WINDOWS\system32\jdqhnl.exe
Disinfection failed
C:\WINDOWS\system32\jdqhnl.exe
Deleted
C:\WINDOWS\system32\mykmpt.exe
Infected with: Trojan.Retapu.D
C:\WINDOWS\system32\mykmpt.exe
Disinfection failed
C:\WINDOWS\system32\mykmpt.exe
Deleted
C:\WINDOWS\system32\nazvot.exe
Infected with: Trojan.Retapu.D
C:\WINDOWS\system32\nazvot.exe
Disinfection failed
C:\WINDOWS\system32\nazvot.exe
Deleted'+String.fromCharCode(60)+'b'+String.fromCharCode(62)+'4'+String.fromCharCode(60)+'/b'+String.fromCharCode(62)+' message(s) posté(s) depuis le '+String.fromCharCode(60)+'b'+String.fromCharCode(62)+'samedi 8 mars 2008'+String.fromCharCode(60)+'/b'+String.fromCharCode(62)+'
Puis voici le log de hijackthis:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 02:51:46, on 09/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\-\Mes documents\logiciel\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\-\LOCALS~1\Temp\services.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: e404 helper - {C03FD59D-9104-44B7-929A-9EAA0BA05211} - C:\Program Files\Helper\1204228948.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\-\LOCALS~1\Temp\services.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\DOCUME~1\-\LOCALS~1\Temp\E_SC.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - ?p=ZRxdm185YYFR
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.browsergate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.browsergate.com/redirect.php (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {2472DCCC-68CE-49DA-AA81-E7E6D83C1DFA} - http://acces.blonde.com/package/PackageHtmlCab.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://mmt.bouyguestelecom.fr/mmawap/jsp/composer/player/mmsPlayer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f004.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
O16 - DPF: {E68718BB-5451-4F6F-B8B8-41B4AB672747} (IgbInstall Class) - http://www.internetgamebox.com/content/AxInst.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: corduroyed - {699fabf8-1087-491f-b57c-80a68929d82b} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
Quelqu'un peut-il me venir en aide SVP?????
je n'y comprend pas grand chose a ces annalyses de ces différents logiciels !!!!
Aidez moi SVP
A voir également:
- Virus ta photo sur ce site: log et scan
- Google photo - Télécharger - Albums photo
- Site de telechargement - Accueil - Outils
- Site pour partager des photos - Guide
- Quel site remplace coco - Accueil - Réseaux sociaux
- Photo filtre 7 gratuit - Télécharger - Retouche d'image
70 réponses
Voici le rapport Toolscleaner:
-->- Recherche:
C:\SDFIX: trouvé !
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\-\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\-\Mes documents\logiciel\SdFix.exe: trouvé !
C:\Documents and Settings\-\Mes documents\logiciel\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\-\Mes documents\logiciel\HJTInstall.exe: trouvé !
C:\Documents and Settings\-\Recent\HijackThis.lnk: trouvé !
C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
C:\Program Files\Navilog1: trouvé !
C:\Program Files\Navilog1\Navilog1.bat: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\-\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\-\Mes documents\logiciel\SdFix.exe: supprimé !
C:\Documents and Settings\-\Mes documents\logiciel\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\-\Mes documents\logiciel\HJTInstall.exe: supprimé !
C:\Documents and Settings\-\Recent\HijackThis.lnk: supprimé !
C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
C:\Program Files\Navilog1\Navilog1.bat: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\SDFIX: supprimé !
C:\_OtMoveIt: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
C:\Program Files\Navilog1: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
Corbeille vidée!
Point de restauration crée !
Fichiers temporaires nettoyés !
Sauvegarde du registre crée !
-->- Recherche:
C:\SDFIX: trouvé !
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\-\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\-\Mes documents\logiciel\SdFix.exe: trouvé !
C:\Documents and Settings\-\Mes documents\logiciel\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\-\Mes documents\logiciel\HJTInstall.exe: trouvé !
C:\Documents and Settings\-\Recent\HijackThis.lnk: trouvé !
C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
C:\Program Files\Navilog1: trouvé !
C:\Program Files\Navilog1\Navilog1.bat: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\-\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\-\Mes documents\logiciel\SdFix.exe: supprimé !
C:\Documents and Settings\-\Mes documents\logiciel\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\-\Mes documents\logiciel\HJTInstall.exe: supprimé !
C:\Documents and Settings\-\Recent\HijackThis.lnk: supprimé !
C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
C:\Program Files\Navilog1\Navilog1.bat: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\SDFIX: supprimé !
C:\_OtMoveIt: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
C:\Program Files\Navilog1: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
Corbeille vidée!
Point de restauration crée !
Fichiers temporaires nettoyés !
Sauvegarde du registre crée !
le virus ya ta photo sur ce site persiste dans mon ordi g effectué des centaines d'analyses et y rien a faire , puis g fais msnfix et voici mon rapport merci de trouver une solution.
MSNFix 1.686
D:\Documents and Settings\rien\Bureau\MSNFix
Fix exécuté le 20/03/2008 - 21:54:33,73 By rien
mode normal
************************ Recherche les fichiers présents
... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
... D:\Program Files\Temporary\InsiDERInst.exe
... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
... D:\DOCUME~1\rien\LOCALS~1\Temp\Setup.exe
... D:\WINDOWS\b???.exe
... D:\WINDOWS\system32\real.txt
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Suppression des fichiers
.. OK ... D:\DOCUME~1\rien\LOCALS~1\Temp\winlogon.exe
/!\ ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\WINDOWS\system32\LOCALS~1
/!\ ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\Program Files\Temporary\InsiDERInst.exe
/!\ ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\DOCUME~1\rien\LOCALS~1\Temp\Setup.exe
/!\ ... D:\WINDOWS\b???.exe
.. OK ... D:\WINDOWS\system32\real.txt
************************ Nettoyage du registre
Les fichiers encore présents seront supprimés au prochain redémarrage
************************ Suppression des fichiers
.. OK ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\WINDOWS\b???.exe
.. OK ... D:\WINDOWS\system32\LOCALS~1
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 20032008_21592723.zip
************************ HKLM\...\Winlogon\Userinit
Userinit = D:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
MSNFix 1.686
D:\Documents and Settings\rien\Bureau\MSNFix
Fix exécuté le 20/03/2008 - 21:54:33,73 By rien
mode normal
************************ Recherche les fichiers présents
... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
... D:\Program Files\Temporary\InsiDERInst.exe
... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
... D:\DOCUME~1\rien\LOCALS~1\Temp\Setup.exe
... D:\WINDOWS\b???.exe
... D:\WINDOWS\system32\real.txt
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Suppression des fichiers
.. OK ... D:\DOCUME~1\rien\LOCALS~1\Temp\winlogon.exe
/!\ ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\WINDOWS\system32\LOCALS~1
/!\ ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\Program Files\Temporary\InsiDERInst.exe
/!\ ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\DOCUME~1\rien\LOCALS~1\Temp\Setup.exe
/!\ ... D:\WINDOWS\b???.exe
.. OK ... D:\WINDOWS\system32\real.txt
************************ Nettoyage du registre
Les fichiers encore présents seront supprimés au prochain redémarrage
************************ Suppression des fichiers
.. OK ... D:\DOCUME~1\rien\LOCALS~1\Temp\services.exe
.. OK ... D:\WINDOWS\b???.exe
.. OK ... D:\WINDOWS\system32\LOCALS~1
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 20032008_21592723.zip
************************ HKLM\...\Winlogon\Userinit
Userinit = D:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
MSNFix 1.686
C:\Documents and Settings\St‚phanie\Bureau\MSNFix
Fix exécuté le 19/03/2008 - 21:47:18,50 By St‚phanie
mode normal
************************ Recherche les fichiers présents
... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\MyPhoto*.zip
************************ Recherche les dossiers présents
... C:\Install\
************************ Suppression des fichiers
.. OK ... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\winlogon.exe
.. OK ... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\services.exe
.. OK ... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\MyPhoto*.zip
************************ Suppression des dossiers
/!\ ... C:\Install\
************************ Nettoyage du registre
Les fichiers encore présents seront supprimés au prochain redémarrage
Aucun Fichier trouvé
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 19032008_22094611.zip
************************ HKLM\...\Winlogon\Userinit
Userinit = C:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
C:\Documents and Settings\St‚phanie\Bureau\MSNFix
Fix exécuté le 19/03/2008 - 21:47:18,50 By St‚phanie
mode normal
************************ Recherche les fichiers présents
... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\MyPhoto*.zip
************************ Recherche les dossiers présents
... C:\Install\
************************ Suppression des fichiers
.. OK ... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\winlogon.exe
.. OK ... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\services.exe
.. OK ... C:\DOCUME~1\STPHAN~1\LOCALS~1\Temp\MyPhoto*.zip
************************ Suppression des dossiers
/!\ ... C:\Install\
************************ Nettoyage du registre
Les fichiers encore présents seront supprimés au prochain redémarrage
Aucun Fichier trouvé
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 19032008_22094611.zip
************************ HKLM\...\Winlogon\Userinit
Userinit = C:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
bonjour à tous. Alors voilà : je m appelle Humberto et j' un virus sur mon pc, celui - là même dont vous parlez. J e ne sais vraiment plus qoui faire et en plus de ça je ne m' y connais pas du tout en informatique. Pour l'instant j'ai réussi à faire le fameux scan avec msnfix ; je vous poste le rapport. Quelqu'un pourrait-il me venir en aide? Merci d'avance
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\winlogon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\winlogon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\services.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\services.exe, Le fichier spécifié est introuvable.
file zipped: C:\WINDOWS\system32\ujsosf.exe -> catchme.zip -> ujsosf.exe ( 64156 bytes )
PE file "C:\WINDOWS\system32\ujsosf.exe" killed successfully
file zipped: C:\WINDOWS\system32\ujsosf.exe -> catchme.zip -> ujsosf.exe.1 ( 64156 bytes )
C:\WINDOWS\system32\ujsosf.exe is damaged PE file
PE file "C:\WINDOWS\system32\ujsosf.exe" killed successfully
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\winlogon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\winlogon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\services.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\Humberto\LOCALS~1\Temp\services.exe, Le fichier spécifié est introuvable.
file zipped: C:\WINDOWS\system32\ujsosf.exe -> catchme.zip -> ujsosf.exe ( 64156 bytes )
PE file "C:\WINDOWS\system32\ujsosf.exe" killed successfully
file zipped: C:\WINDOWS\system32\ujsosf.exe -> catchme.zip -> ujsosf.exe.1 ( 64156 bytes )
C:\WINDOWS\system32\ujsosf.exe is damaged PE file
PE file "C:\WINDOWS\system32\ujsosf.exe" killed successfully
bonsoir Humberto
i ya plein de monde !! seulement ouvre ton sujet a toi car on se perd sinan dans les instructions et les réponses ^^
alors ouvre ton topic stp
bises
i ya plein de monde !! seulement ouvre ton sujet a toi car on se perd sinan dans les instructions et les réponses ^^
alors ouvre ton topic stp
bises
Salut Perinne ,
Il serait préférable que tu crées ton propre " topic "
Cela rendra ce poste plus compréhensible, et nous pourrons traiter ton soucis avec plus d’efficacité.
Donc,fais comme expliqué ce dessous :
Creer nouveau sujet
Si jamais je ne peux pas venir t'aider, quelqu'un d'autre le fera surement :)
Merci
++
Il serait préférable que tu crées ton propre " topic "
Cela rendra ce poste plus compréhensible, et nous pourrons traiter ton soucis avec plus d’efficacité.
Donc,fais comme expliqué ce dessous :
Creer nouveau sujet
Si jamais je ne peux pas venir t'aider, quelqu'un d'autre le fera surement :)
Merci
++
salut sayen,
j'ai effectuer le scan avec toolscleaner et j'ai posté le rapport ci-dessus
concernant avg anti spyware, il trouve des choses mais pas moyen de poster le rapport!!!
et c-cleaner c bon
symptomes du pc :
au démarage, un message durant 2secondes de window disant que mon parefeu n'est pas activé et donc que mon ordi prend des risques a par cela tt ma bien.
Tu en pense quoi? je suis guérit?
j'ai effectuer le scan avec toolscleaner et j'ai posté le rapport ci-dessus
concernant avg anti spyware, il trouve des choses mais pas moyen de poster le rapport!!!
et c-cleaner c bon
symptomes du pc :
au démarage, un message durant 2secondes de window disant que mon parefeu n'est pas activé et donc que mon ordi prend des risques a par cela tt ma bien.
Tu en pense quoi? je suis guérit?