Rav scan online..Fch infectés-
unsect
-
Utilisateur anonyme -
Utilisateur anonyme -
Salut! Symantec corporate ne malerte que de temps en temps pourtant en effectuant un scan online sur rav..voila ce ke ca me donne...le problem cest ke je ne my connai pa trop et je voudrai savoir comment se debarasser de ces fichiers infectés.....
:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Boîte de réception.dbx->Message.29: (3da.vigier@free.fr [error])->(part0002:mails.zlo) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Boîte de réception.dbx->Message.21: (Service de distribution du courrier [=?ISO-8859-15?Q?Notification_d'=E9tat_de_l... - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.21: (irneblaise@yahoo.fr [msg])->(part0002:auction.zlq) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.20: (vincentlhopiteau@aol.com [notification])->(part0002:death.zl6) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.19: (alain.leclercq18@libertysurf.fr [hello])->(part0002:nothing.txt.zlq) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.17: (delphine.hubo@cdn.fr [Re: <5664ddff?$??§2>])->(part0002:website.zlq) - Win32/Netsky.C@mm -> Infected
C:\Program Files\FLoopStudio\Plugins\backup-20040529-120601-567.dll - TrojanDownloader:Win32/IstBar.EN -> Infected
C:\System Volume Information\_restore{2DD9FE96-FBD9-4BDE-9CF1-75843BE9288E}\RP24\A0003562.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
C:\System Volume Information\_restore{2DD9FE96-FBD9-4BDE-9CF1-75843BE9288E}\RP24\A0003564.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
C:\WINDOWS\Downloaded Program Files\photos-trans-org-t.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
C:\WINDOWS\system32\netia32.dll - Trojan:Win32/Trilon.A -> Infected
C:\WINDOWS\system32\P2ECOM.dll - Trojan:Win32/P2E.C -> Infected
C:\WINDOWS\system32\XXX_Action-uninstall.exe - Tool:PornDialer.IE -> Infected
Scanned
============================
Objects: 53843
Directories: 4272
Archives: 6648
Size(Kb): -618778
Infected files: 13
Found
============================
Viruses found: 6
Suspicious files: 0
Disinfected files: 0
Mail files: 351
merci davance pour votre aide!! bye
:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Boîte de réception.dbx->Message.29: (3da.vigier@free.fr [error])->(part0002:mails.zlo) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Boîte de réception.dbx->Message.21: (Service de distribution du courrier [=?ISO-8859-15?Q?Notification_d'=E9tat_de_l... - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.21: (irneblaise@yahoo.fr [msg])->(part0002:auction.zlq) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.20: (vincentlhopiteau@aol.com [notification])->(part0002:death.zl6) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.19: (alain.leclercq18@libertysurf.fr [hello])->(part0002:nothing.txt.zlq) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.17: (delphine.hubo@cdn.fr [Re: <5664ddff?$??§2>])->(part0002:website.zlq) - Win32/Netsky.C@mm -> Infected
C:\Program Files\FLoopStudio\Plugins\backup-20040529-120601-567.dll - TrojanDownloader:Win32/IstBar.EN -> Infected
C:\System Volume Information\_restore{2DD9FE96-FBD9-4BDE-9CF1-75843BE9288E}\RP24\A0003562.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
C:\System Volume Information\_restore{2DD9FE96-FBD9-4BDE-9CF1-75843BE9288E}\RP24\A0003564.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
C:\WINDOWS\Downloaded Program Files\photos-trans-org-t.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
C:\WINDOWS\system32\netia32.dll - Trojan:Win32/Trilon.A -> Infected
C:\WINDOWS\system32\P2ECOM.dll - Trojan:Win32/P2E.C -> Infected
C:\WINDOWS\system32\XXX_Action-uninstall.exe - Tool:PornDialer.IE -> Infected
Scanned
============================
Objects: 53843
Directories: 4272
Archives: 6648
Size(Kb): -618778
Infected files: 13
Found
============================
Viruses found: 6
Suspicious files: 0
Disinfected files: 0
Mail files: 351
merci davance pour votre aide!! bye
3 réponses
-
Bonjour!
a priori tu as des mails infectés:
:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Boîte de réception.dbx->Message.29: (3da.vigier@free.fr [error])->(part0002:mails.zlo) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Boîte de réception.dbx->Message.21: (Service de distribution du courrier [=?ISO-8859-15?Q?Notification_d'=E9tat_de_l... - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.21: (irneblaise@yahoo.fr [msg])->(part0002:auction.zlq) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.20: (vincentlhopiteau@aol.com [notification])->(part0002:death.zl6) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.19: (alain.leclercq18@libertysurf.fr [hello])->(part0002:nothing.txt.zlq) - Win32/Netsky.C@mm -> Infected
C:\Documents and Settings\Yves\Local Settings\Application Data\Identities\{DD31417D-58D3-4DCA-957B-75CA00C4091A}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.17: (delphine.hubo@cdn.fr [Re: <5664ddff?$??§2>])->(part0002:website.zlq) - Win32/Netsky.C@mm -> Infected
y'en a dans ta boite de réception, dans tes messages suprimés, et je crois dans ta boite d'nvoi.
Ensuite
C:\System Volume Information\_restore{2DD9FE96-FBD9-4BDE-9CF1-75843BE9288E}\RP24\A0003564.exe->(UPXW) - Tool:PornDialer.gen! -> Infected
désactives ta restauration et réactives-la
Pour le reste, supprimes les fichiers, sauf ceux qui ont une extention .dll, ceux là attend que quelqu'un te dise quoi faire.
@+ -
salut pour les dll tu peu les suprimer aussi en mode sanns echec (redemarage + tapotte sans cesse sur f8 desque ton ordi s'allume )
@++ -
salut voila comment desactiver la restauration:
clike droit sur post de travaille/proprietes/restauration system et la tu coche desactiver la restauration du systeme tu applique
à+++