(VIRUS) Type Sasser
Je me suis fais avoir comme un mauvais :(
J'ai démarré un install (qui en fait a placé le virus dans le fichier temp et l'a executé).
Immédiatement FSecure le detecte mais bon trop tard, le systeme est forcé de redémarrer avec un compte à rebours.
Je redémarre en mode sans echec et je passe un coup d'AVG antispyware qui me detecte un trojan (mais je doute que ce soit le virus que je viens de chopper.
J'éteins mon ordi pour aller me coucher, je redémarre en mode sans echec, je passe l'outil de symantec pour Sasser qui me dit que mon ordinateur n'est pas infecté.
Je redémarre normalement, là j'ai plusieurs fenetres d'erreurs qui apparaissent concernant des processus (le BackWeb de FSecure et des processus PnkBst je crois que c'est punkbuster). Ces messages sont des erreurs de lecture en mémoire.
Mis à part ca, ca a fonctionné. Mais à un moment j'ai eu un Blue screen et quand j'ai redémarré le virus était de retour.
Ci-apres le rapport HijackThis fait en mode sans echec :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:36:36, on 26/02/2088
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Logiciels\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Logiciels\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Logiciels\TortoiseSVN\bin\TSVNCache.exe
C:\Logiciels\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.incompris.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\fccdeFXo.dll
O2 - BHO: C:\WINDOWS\system32\hhs3ijndfd.dll - {c5bf49a2-94f3-42bd-f434-3604812c8955} - C:\WINDOWS\system32\hhs3ijndfd.dll
O3 - Toolbar: Alcohol Toolbar - {4C4E7CDB-5BFC-4D74-83E2-8AE659B7EDA2} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [EPSON Stylus Photo RX520 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAGE.EXE /P31 "EPSON Stylus Photo RX520 Series" /M "Stylus Photo RX520" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [settings] C:\WINDOWS\callsysnt.exe
O4 - HKCU\..\RunOnce: [RegistryDefrag Success Message] "C:\Logiciels\TuneUp Utilities\TUMessages.exe" /RegDefrag_Success
O4 - HKLM\..\Policies\Explorer\Run: [xccinit] C:\WINDOWS\system32\inf\rundll33.exe C:\WINDOWS\xccdf16_090131a.dll xccd16
O4 - HKCU\..\Policies\Explorer\Run: [settings] C:\WINDOWS\callsysnt.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: TÈlÈcharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: TÈlÈcharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: TÈlÈcharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Envoyer ‡ OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer ‡ OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Michael\Jeux\Poker\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Michael\Jeux\Poker\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.incompris.net/
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {91D4B4D5-E368-40AB-8F53-A37FA634B471} (Installer9Ctrl Class) - http://www2.tellmemorecampus.com/bin/tol9inst.cab
O16 - DPF: {9B14B03A-B482-45C3-BE37-5B7CAA8B0B5D} (QBH Control) - http://hsearch.nayio.com/download/QBH.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O20 - Winlogon Notify: fccdeFXo - C:\WINDOWS\SYSTEM32\fccdeFXo.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hhs3ijndfd.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Logiciels\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Logiciels\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure BackWeb (backweb client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Service de transfert intelligent en arriËre-plan (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: F-Secure BackWeb LAN Access (f-secure backweb lan access) - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Logiciels\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\WINDOWS\Private Folder\PrfldSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - C:\Logiciels\wamp\bin\apache\apache2.2.10\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - C:\Logiciels\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
--
End of file - 10432 bytes
Donc au final il a eu mon antivirus qui ne fonctionne plus :P J'ai cru lire sur d'autres forum qu'un rapport hijackthis n'était pas approprié pour ce genre de virus.
Merci par avance pour votre aide.
Cordialement,
Toast.
166 réponses
Une infection par virus survient après une installation qui place le malware dans le dossier temporaire et le lance immédiatement, F-Secure le détectant mais le système redémarrant ensuite avec un compte à rebours. En mode sans échec, des scans successifs ( AVG, Symantec pour Sasser ) ne rassurent pas, des messages d'erreur mémoire apparaissent pour des processus comme BackWeb et PnkBstr. Le rapport HijackThis en mode sans échec montre de multiples entrées IE, des redirections 127.0.0.1:8080 et des DLL modifiées, ce qui complexifie l’analyse. Certains recommandent d’éviter les interprétations d’un seul rapport et d’opter pour une désinfection complète via des outils dédiés, tout en restant prudent sur les sauvegardes et le nettoyage des processus système.
-
ah pas bête
-
Non :P Enfin il y est sur le CD Xp Pro, mais vu qu'apperement j'ai corporate, j'ose pas le lancer :P
-
ok as-tu trouvé ton WINNT32.exe ?
-
Salut.
Je passe juste pour vous dire que Antivir est de retour dans ma barre des taches (meme si en double cliquant il n'affiche pas le menu :P )
J'ai fais un MalwareByte et Spyware Terminator, ils ont peut etre débloqué un truc :) En tout cas c'est cool (enfin je restais intrigué avant pcque j'avais toujours les popups d'antivir :P ) -
le 32 Bits rapporte encore trop !!! :)
-
Par contre, à quand le 64bits par défaut ?
-
Au moins j'aurais pas connu Vista :P = + 100000000000000000
-
Windows 7 a que coucou!!!!
-
ben moi le mien il beugue grave en fait :( trop de progs installés non compatibles peut etre (d'ailleur je vois que ca )
-
J'en attends pas mal de windows 7 quand même. J'ai des copains qui le teste et apparement ca suit bien.
Au moins j'aurais pas connu Vista :P -
salut :
Windows XP normal.
c'est le mieux en fait :)
-
J'ai posté sur le forum d'avira et on m'a conseillé de faire la réparation windows. Mais je viens de voir qu'en fait j'avais installé la version corporate de mon unattended :P
Enfin de toute facon sur le CD de boot, il n'y a pas de winnt32.exe qui permet de faire la réparation.
J'ai un cd XP pro mais je ne suis pas sur que ce soit les memes fichiers (enfin j'ai lu que la seule difference c'était que les clefs en corporate pouvaient être utilisées plusieurs fois).
Quoiqu'il en soit, je pense que je vais installer un autre antivirus gratuit en attendant. Et peut-etre que pendant les vacances je passerais tout simplement sur un Windows XP normal.
En tout cas merci à tous ceux qui ont participé au nettoyage de mon PC, c'est vraiment sympa. -
sans outil :
Pour désinstaller AntiVir, faîtes un clic droit sur l'icône d'Antivir dans la barre des tâches (en bas à droite), cliquez sur "Antivir Guard enable" afin de le désactiver puis désinstallez le programme à partir de l'outil Ajout/suppression de programmes qui se trouve dans le Panneau de configuration. -
Non mais l'outil c'est pas un removal du logiciel, mais :
For all those experiencing the damaging effects of a virus infection, Avira’s researchers have prepared a removal tool, which can be used to eliminate major distinct threats.
Donc je ne sais pas trop que faire :P -
Hmm bah j'ai toujours pas d'antivirus fonctionnel, et je ne sais pas pourquoi :P
reeassaie de desinstaller avec l outil et redemarrer et reinstaller -
Ne te prends pas la tête pour les autorun.inf je les ai déjà nettoyé. A mon avis, ils ne peuvent pas être touché pcque je les ai créé avec le logiciel Flash disinfector. Et puis ceux sont des dossiers dans le cas présent. C'est pour empecher justement le virus se propageant pas les DD et clef USB de remplacer les fichiers saints par les fichiers vérolés.
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
Folder move failed. D:\autorun.inf scheduled to be moved on reboot.
Folder move failed. G:\autorun.inf scheduled to be moved on reboot.
C:\WINDOWS\System32\3712495756.dat moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03192009_203825
Files moved on Reboot...
Folder move failed. D:\autorun.inf scheduled to be moved on reboot.
Folder move failed. G:\autorun.inf scheduled to be moved on reboot. -
redemarres en mode sans echec total et copies le dans un doc.txt que tu retrouveras sur ton bureau en mode sans echec pour le copier dans otmoveit :
:processes
explorer.exe
:files
D:\autorun.inf
G:\autorun.inf
C:\WINDOWS\System32\3712495756.dat
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
-
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== FILES ==========
Folder move failed. D:\autorun.inf scheduled to be moved on reboot.
G:\autorun moved successfully.
Folder move failed. G:\autorun.inf scheduled to be moved on reboot.
C:\WINDOWS\sed.exe moved successfully.
File move failed. C:\WINDOWS\System32\3712495756.dat scheduled to be moved on reboot.
C:\WINDOWS\System32\drivers\etc\hosts.msn moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_8EjTYjQWl50ilOEhU8IB scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents And Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2ac.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03192009_193309
Files moved on Reboot...
Folder move failed. D:\autorun.inf scheduled to be moved on reboot.
Folder move failed. G:\autorun.inf scheduled to be moved on reboot.
File move failed. C:\WINDOWS\System32\3712495756.dat scheduled to be moved on reboot.
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_8EjTYjQWl50ilOEhU8IB not found!
File move failed. C:\Documents And Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_2ac.dat not found!
C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_001_ moved successfully.
C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_002_ moved successfully.
C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_003_ moved successfully.
C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents And Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\dydk4s6j.default\urlclassifier3.sqlite moved successfully. -
---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
:files
D:\autorun.inf
G:\autorun
G:\autorun.inf
C:\WINDOWS\sed.exe
C:\WINDOWS\System32\3712495756.dat
C:\WINDOWS\System32\drivers\etc\hosts.msn
:reg
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
-
http://www.cijoint.fr/cjlink.php?file=cj200903/cijTH5ApFp.txt
Le rapport Extra se trouve a la suite du premier rapport.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9