Suppression virus Trojan.Domcom

Un grand merci à Balltrap pour son programme permettant d'éradiquer Trajan.Domcom. Ca marche.
Salut

24 réponses

Résumé de la discussion

Un grand merci à Balltrap pour son programme permettant d’éradiquer Trojan.Domcom et les échanges décrivent les résultats positifs et les difficultés rencontrées par les utilisateurs. La meilleure réponse recommande d’afficher les fichiers et dossiers cachés, de décocher l’option masquant les fichiers système protégés et d’appliquer les changements pour révéler les emplacements potentiels du Trojan.Domcom. D’autres réponses décrivent des difficultés complémentaires, notamment l’impossibilité de retirer le trojan via Norton et l’éventualité d’un fichier ipreg32.dll associé, avec des analyses et des retours d’expériences. En cas de persistance, certains participants évoquent une reprise de l’aide demain et l’étendue des échanges montre une collaboration continue malgré les blocages.

Bobot (l’IA à votre service)
  1. salut

    supprime le manuellement.

    rend visible les dossiers cachés:
    panneau de configuration > options des dossiers > onglet affichage
    cocher " afficher les fichiers et dossiers cachés "
    décocher " masquer les extentions des fichiers dont le type est connu

    puis va dans :
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\double clic sur Content.IE5
    supprime tous les dossiers sauf le fichier index.dat

    a+
    0
    1. alors tu les refais qd meme (avec le lien je t ai mis au dessu puis tu redemarres) et tu lance un scan chez RAV :
      http://www.ravantivirus.com/scan/

      Clique sur "To continue without subscribing click here" et attends quelques minutes.
      Lorsque "Ready" est affiché dans "status", coche la case "Autoclean" puis clique sur "Scan my PC"
      A la fin de l'analyse, copie/colle le rapport ici
      0
      1. scanravest toujours occupé.
        mercipour ta patience.
        0
      2. Scan started at 30/04/2005 20:34:38

        Scanning memory...
        Scanning boot sectors...
        Scanning files...
        C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\D4EBCZJG\v3cab[1].cab->v3.dll - HackTool:Win32/Simple.A -> Infected

        voici le résultat de scanrav

        Scanned
        ============================
        Objects: 50103
        Directories: 2908
        Archives: 5961
        Size(Kb): 1554963
        Infected files: 1

        Found
        ============================
        Viruses found: 1
        Suspicious files: 0
        Disinfected files: 0
        Mail files: 29
        0
    2. salut:

      Fais un nettoyage des fichiers temps...etc avec ce programme:
      http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

      ensuite redemarre ton pc !

      et dis moi ou en sont tes problemes !!

      a+
      0
      1. Regis, j'ai fait les différentes opérations et le trojan est toujours présent.
        0
    3. les differents rapports que tu as fait ! ceux de norton, ceux de cleenup, ceux de rav car je ne sais pas ou tu en est et tu me dis tes soucis persistes, donc je prend le sujet en cours , ca serait bien tu me mette tes scans les plus recents de norton, cleenup, RAV...

      a+
      0
      1. pour scanup voici:CleanUp! started on 04/30/05 19:27:00.
        ...
        http://r6.kelkoo.com/misc/footer_icon_info.gif - deleted
        http://europe.adserver.yahoo.com/a?f=2124610235&p=bekkcomp&l=SKY&c=sr - deleted
        www.pcentraide.com%2Findex.php%3Fact%3DUserCP%26CODE%3D00&color_bg=F5F5F5&color_tex' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114880072945&lmt=1114880072&format=728x90_as&output=html&channel=0060263680&url=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DUserCP%26CODE%3D00&color_bg=F5F5F5&color_tex - deleted
        www.pcentraide.com%2F&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D01&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=20&u_java=true' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114880134123&lmt=1114880134&format=728x90_as&output=html&channel=8861617361&url=http%3A%2F%2Fwww.pcentraide.com%2F&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D01&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=20&u_java=true - deleted
        http://www.pcentraide.com/informatique/virus.jpg - deleted
        http://www.pcentraide.com/uploads/av-245.jpg - deleted
        http://www.pcentraide.com/index.php?act=Search&CODE=01 - deleted
        http://www.pcentraide.com/phps/php-stats.php?w=1024&h=768&c=32&f=http%3A//www.pcentraide.com/index.php%3Fact%3Didx&NS_url=http%3A//www.pcentraide.com/index.php%3Fshowuser%3D3&t=Affichage%20d%27un%20profil - deleted
        http://r6.kelkoo.com/misc/footer_icon_contact.gif - deleted
        http://r6.kelkoo.com/scripts/rd/crawlers.js - deleted
        http://www.pcentraide.com/phps/php-stats.php?w=1024&h=768&c=32&f=http%3A//www.pcentraide.com/lofiversion/index.php/t611.html&NS_url=http%3A//www.pcentraide.com/index.php%3Fact%3DMembers&t=La%20liste%20des%20membres - deleted
        http://dhnet.metriweb.be/sd/dhnet/mw.cgi?page=homepage&q=fr&c=0001114875051.335822.5&v=3.0&R=0.36402543004192345 - deleted
        http://logv12.xiti.com/hit.xiti?s=52543&p=_forum_affich-1449192&hl=19x21x39&r=1024x768xundefinedx32&ref=http://www.commentcamarche.net/forum/ajout.php3 - deleted
        http://www.pcentraide.com/index.php?act=UserCP&CODE=26 - deleted
        http://www.pcentraide.com/index.php?act=Msg&CODE=01&VID=in&sort=name&st= - deleted
        http://r6.kelkoo.com/css/kelkoo_61_fr_BE_KELKOO_1.css - deleted
        http://www.dhnet.be/imagette_pdf/dh_pdf.jpg?time=1114881351 - deleted
        http://r6.kelkoo.com/misc/footer_bg.gif - deleted
        http://fr.kelkoo.be/images/be/sponsor/belcenter/visu60adsl.jpg - deleted
        http://www.pcentraide.com/phps/php-stats.php?w=1024&h=768&c=32&f=&NS_url=http%3A//www.pcentraide.com/index.php&t=PC%20entraide%2C%20forum%20aide%20informatique - deleted
        http://www.commentcamarche.net/forum/affich-1483869 - deleted
        www.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3Ddelete&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D03%26VID%3Din%26MSID%3D2052&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=22&u_java=true' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114880637888&lmt=1114880637&prev_fmts=728x90_as&format=728x90_as&output=html&channel=3909659384&url=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3Ddelete&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D03%26VID%3Din%26MSID%3D2052&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=22&u_java=true - deleted
        www.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D03%26VID%3Din%26MSID%3D2052&col' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114880890621&lmt=1114880890&format=728x90_as&output=html&channel=0060263680&url=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D03%26VID%3Din%26MSID%3D2052&col - deleted
        http://dhnet.metriweb.be/sd/dhnet/mw.cgi?page=homepage&q=fr&c=0001114875051.335822.5&v=3.0&R=0.06723461946074321 - deleted
        http://logv12.xiti.com/hit.xiti?s=52543&p=_forum_affich-1449192-Suppression-virus-Trojan-Domcom&hl=19x16x21&r=1024x768xundefinedx32&ref= - deleted
        www.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D01%26VID%3D' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114880896740&lmt=1114880896&prev_fmts=728x90_as&format=728x90_as&output=html&channel=3909659384&url=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMsg%26CODE%3D01%26VID%3D - deleted
        http://r6.kelkoo.com/misc/footer_right.gif - deleted
        http://www.pcentraide.com/phps/php-stats.php?w=1024&h=768&c=32&f=http%3A//www.pcentraide.com/lofiversion/index.php/f6.html&NS_url=http%3A//www.pcentraide.com/lofiversion/index.php/t611.html&t=PC%20entraide%20%3E%20virus%20tenaces - deleted
        www.pcentraide.com%2Findex.php%3Fact%3Dmembers&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMembers&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=4&u_java=true' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114881213105&lmt=1114881213&format=728x90_as&output=html&channel=0060263680&url=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3Dmembers&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fact%3DMembers&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=4&u_java=true - deleted
        http://www.pcentraide.com/phps/php-stats.php?w=1024&h=768&c=32&f=http%3A//www.pcentraide.com/index.php%3Fs%3D515e784de724323ebab72ae70f389e06%26showuser%3D744&NS_url=http%3A//www.pcentraide.com/index.php%3F&t=PC%20entraide%2C%20forum%20aide%20informatique - deleted
        http://logv12.xiti.com/hit.xiti?s=52543&p=_forum_ajout.php3&hl=19x19x56&r=1024x768xundefinedx32&ref=http://www.commentcamarche.net/forum/affich-1449192?page=1 - deleted
        http://logv27.xiti.com/hit.xiti?s=188930&p=&hl=19x16x6&r=1024x768xundefinedx32&ref= - deleted
        http://logv12.xiti.com/hit.xiti?s=52543&p=_forum_affich-1449192&hl=19x19x59&r=1024x768xundefinedx32&ref=http://www.commentcamarche.net/forum/ajout.php3 - deleted
        www.pcentraide.com%2Findex.php%3Fs%3D515e784de724323ebab72ae70f389e06%26showuser%3D744&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=1&u_java=true' target='_blank' rel='nofollow'>http://pagead2.googlesyndication.com/pagead/ads?client=ca-pub-3979408414468186&dt=1114881273352&lmt=1114881273&prev_fmts=728x90_as&format=728x90_as&output=html&channel=3909659384&url=http%3A%2F%2Fwww.pcentraide.com%2Findex.php%3Fs%3D515e784de724323ebab72ae70f389e06%26showuser%3D744&color_bg=F5F5F5&color_text=666666&color_link=000000&color_url=666666&color_border=F5F5F5&ad_type=text&ref=http%3A%2F%2Fwww.pcentraide.com%2Findex.php&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_tz=120&u_his=1&u_java=true - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\QTLEB698\2521.468x60_JB_3fr[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\QTLEB698\2445.skyscraper_enfant_fr[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\QTLEB698\index[1].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\2521.468x60_JB_3fr[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\index[1].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\ACC_RANDOM=1114875193619[1] - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\index[1].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\ajout[1].php3 - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\affich-1483869[1] currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WPYRGDI7\2445.banner_crane_fr[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WPYRGDI7\index[1].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WPYRGDI7\index[2].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\81EFMNCP\AAMSZ=1X1[1] - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\QHSNI149\ajout[1].php3 - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\QHSNI149\index[2].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\QHSNI149\index[3].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\Y7YHQ50X\ACC_RANDOM=1114875050594[1] - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\Y7YHQ50X\ACC_RANDOM=1114875052817[1] - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\JI4J3PKP\2521.468x60_JB_3fr[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\0HMRGLUJ\index[1].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\6P5U7YL4\ajout[1].php3 - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\6P5U7YL4\2521.sky_120_fr_bis[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\6P5U7YL4\2521.sky_120_fr[1].swf - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\6P5U7YL4\10160[1].htm - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\HO0O88H2\index[1].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\HO0O88H2\ajout[1].php3 - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\BBP73XCW\AAMSZ=1X1[1] - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\KJ7JM45H\ACC_RANDOM=1114875051695[1] - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\KJ7JM45H\index[2].php - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\OLK58\ - deleted
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\affich-1483869[1] currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\affich-1483869[1] currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\affich-1483869[1] currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Historique\History.IE5\MSHist012005043020050501\index.dat currently in use. Will be deleted when Windows is restarted.
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1483485?page=1 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=01&VID=in - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Login&CODE=03 - deleted
        Visited: Patrick@javascript:unselect_all() - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=01&VID=in&sort=name&st= - deleted
        Visited: Patrick@http://fr.kelkoo.be/b/a/c_100015713_abonnement_adsl.html?kpartnerid=8915228 - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/ajout.php3 - deleted
        Visited: Patrick@http://www.pcentraide.com/lofiversion/index.php/f6.html - deleted
        Visited: Patrick@www.inoculer.com%2Flogo.gif%3BS%3Ahttp%3A%2F%2Fwww.inoculer.com%3BFORID%3A1%3B&hl=fr' target='_blank' rel='nofollow'>http://www.google.com/custom?domains=inoculer.com&q=trojan.domcom&sitesearch=inoculer.com&client=pub-6436802219407199&forid=1&ie=ISO-8859-1&oe=ISO-8859-1&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A000000%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BLH%3A50%3BLW%3A250%3BL%3Ahttp%3A%2F%2Fwww.inoculer.com%2Flogo.gif%3BS%3Ahttp%3A%2F%2Fwww.inoculer.com%3BFORID%3A1%3B&hl=fr - deleted
        Visited: Patrick@res://C:\Program%20Files\Norton%20AntiVirus\NAVComUI.dll/SMTPProgress.htm - deleted
        Visited: Patrick@javascript:emoticon(':help:') - deleted
        Visited: Patrick@javascript:select_read() - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php - deleted
        Visited: Patrick@outlook:%C9l%E9ments%20supprim%E9s - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Members - deleted
        Visited: Patrick@javascript:buddy_pop(); - deleted
        Visited: Patrick@http://www.inoculer.com/virusdesinfection.php3 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?showuser=744 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?&act=Msg&CODE=01 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=4&MID=3 - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1449192-Suppression-virus-Trojan-Domcom - deleted
        Visited: Patrick@http://www.pcentraide.com/lofiversion/index.php/t611.html - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Search&CODE=01 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=4&MID=744 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=01 - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1449192?page=1 - deleted
        Visited: Patrick@www.inoculer.com%2Flogo.gif%3BLH%3A50%3BLW%3A250%3BGL%3A1%3BBGC%3AFFFFFF%3BT%3A%23000000%3BLC%3A%230000ff%3BVLC%3A%23663399%3BALC%3A%230000ff%3BGALT%3A%23008000%3BGFNT%3A%230000ff%3BGIMP%3A%230000ff%3BDIV%3A%23336699%3BLBGC%3A000000%3BAH%3Acenter%3BS%3Ahttp%3A%2F%2Fwww.inoculer.com%3B&domains=inoculer.com&sitesearch=inoculer.com' target='_blank' rel='nofollow'>http://www.google.com/custom?q=trojan.domcom&btnG=Rechercher&hl=fr&ie=ISO-8859-1&oe=ISO-8859-1&client=pub-6436802219407199&cof=FORID%3A1%3BL%3Ahttp%3A%2F%2Fwww.inoculer.com%2Flogo.gif%3BLH%3A50%3BLW%3A250%3BGL%3A1%3BBGC%3AFFFFFF%3BT%3A%23000000%3BLC%3A%230000ff%3BVLC%3A%23663399%3BALC%3A%230000ff%3BGALT%3A%23008000%3BGFNT%3A%230000ff%3BGIMP%3A%230000ff%3BDIV%3A%23336699%3BLBGC%3A000000%3BAH%3Acenter%3BS%3Ahttp%3A%2F%2Fwww.inoculer.com%3B&domains=inoculer.com&sitesearch=inoculer.com - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php? - deleted
        Visited: Patrick@res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?showuser=3 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=buddy - deleted
        Visited: Patrick@file:///C:/Documents%20and%20Settings/Patrick/Mes%20documents/virus%20trojan%20domcom.doc - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Search&f= - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?CODE=05&act=Msg&MSID=2052&VID=in - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1483869 - deleted
        Visited: Patrick@http://www.google.be/fr - deleted
        Visited: Patrick@res://C:\PROGRA~1\NORTON~1\NAVComUI.DLL/CommonUIProgress.htm - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Login&CODE=01 - deleted
        Visited: Patrick@http://www.pcentraide.com/lofiversion/index.php/t757.html - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=UserCP&CODE=00 - deleted
        Visited: Patrick@http://www.google.be - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=idx - deleted
        Visited: Patrick@http://www.virustraq.com/info_virus/10160 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?CODE=01&act=Msg - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=UserCP&CODE=26 - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1483884 - deleted
        Visited: Patrick@res://C:\PROGRA~1\NORTON~1\NAVUI.dll/navstats.htm - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=delete - deleted
        Visited: Patrick@http://www.dhnet.be/index.php - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=01&VID=in&sort=title&st= - deleted
        Visited: Patrick@http://www.dhnet.be/dhsports/article.phtml?id=120515 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Search&nav=lv&CODE=show&searchid=55713e2a0c439e8f971fddc216c00eb5&search_in=topics&result_type=topics&lastdate= - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1483670 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=03&VID=in&MSID=2052 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Msg&CODE=03&VID=in&MSID=2050 - deleted
        Visited: Patrick@http://www.pcentraide.com - deleted
        Visited: Patrick@http://www.commentcamarche.net/forum/affich-1449192 - deleted
        Visited: Patrick@http://www.inoculer.com/scan/licence.php - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Reg&coppa_user=0&termsread=1&coppa_pass=1 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?CODE=04&act=Msg&MID=1&MSID=2050 - deleted
        Visited: Patrick@about:blank - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Reg&CODE=00 - deleted
        Visited: Patrick@outlook:Bo%EEte%20de%20r%E9ception - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Search - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Search&CODE=getnew - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=members - deleted
        Visited: Patrick@outlook:aujourd'hui - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=Login&CODE=00 - deleted
        Visited: Patrick@http://www.pcentraide.com/lofiversion/index.php - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?showforum=6 - deleted
        Visited: Patrick@http://www.google.be/search?hl=fr&q=trojan.domcom&meta=lr%3Dlang_fr - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?CODE=06&act=Msg - deleted
        Visited: Patrick@outlook:Boîte%20de%20réception - deleted
        Visited: Patrick@http://www.inoculer.com/lire2.php?msg=2343 - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?act=SF&s=&f=sj_home - deleted
        Visited: Patrick@http://www.pcentraide.com/index.php?s=515e784de724323ebab72ae70f389e06&showuser=744 - deleted
        'Typed URLs' (Internet Explorer) - removed from the registry.
        Cookie:patrick@metriweb.be/ - deleted
        Cookie:patrick@www.pcentraide.com/ - deleted
        Cookie:patrick@yahoo.com/ - deleted
        Cookie:patrick@www.dhnet.be/ - deleted
        Cookie:patrick@dhnet.be/ - deleted
        Cookie:patrick@kelkoo.be/ - deleted
        Cookie:patrick@fr.kelkoo.be/ - deleted
        Cookie:patrick@google.be/ - deleted
        Cookie:patrick@beweb.com/ - deleted
        Cookie:patrick@mediaplex.com/ - deleted
        Cookie:patrick@google.com/ - deleted
        Cookie:patrick@xiti.com/ - deleted
        Cookie:patrick@doubleclick.net/ - deleted
        C:\Documents and Settings\Patrick\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Recent\virus trojan domcom.lnk - deleted
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\~DFEF16.tmp currently in use. Will be deleted when Windows is restarted.
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\~WRD0000.doc currently in use. Will be deleted when Windows is restarted.
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\~DF962C.tmp currently in use. Will be deleted when Windows is restarted.
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\msohtml1\01\ - deleted
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\msohtml1\ - deleted
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\~DFEF16.tmp currently in use. Will be deleted when Windows is restarted.
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\~WRD0000.doc currently in use. Will be deleted when Windows is restarted.
        C:\DOCUME~1\Patrick\LOCALS~1\Temp\~DF962C.tmp currently in use. Will be deleted when Windows is restarted.
        C:\WINDOWS\temp\rtdrvmon.exe - deleted
        C:\WINDOWS\temp\T30DebugLogFile.txt - deleted
        C:\Documents and Settings\Patrick\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\locals~1\tempor~1\Content.IE5\WTWZG7WB\affich-1483869[1] currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temp\~DFEF16.tmp currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temp\~WRD0000.doc currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temp\~DF962C.tmp currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WTWZG7WB\affich-1483869[1] currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
        'Run MRU' list - removed from the registry.
        WordPad Recent File List - removed from the registry.
        Telnet's MRU list - removed from the registry.
        CleanUp! recovered 4.7 MB of disk space from 923 files.
        CleanUp! finished on 04/30/05 19:27:14.

        pour norton il est dans:ipreg 32.dll, norton me renseigne le chemin suivant C:\windows\system 32\config\systemprofile\local settings\temporary internet file\content.IE5.
        0
    4. Merci Regis mais que veux tu dire par les rapports ceux de norton ou celui de CleanUp?
      0
      1. salut patrick,
        colle les rapports que tu fais, ce sera plus simple pour te conseiller

        a+
        0
        1. Merci Regis mais que veux tu dire par les rapports ceux de norton ou celui de CleanUp?
          0
      2. j'ai un trojan domcom qui est sur ipreg 32.dll, norton me renseigne le chemin suivant C:\windows\system 32\config\systemprofile\local settings\temporary internet file\content.IE5.
        quel est la procédure pour le retirer?
        d'avance merci.
        0
        1. Contributeur sécurité
          0
          1. j'ai télécharger le programme, instalé et lancé,j'ai refais une analyse avec norton et il est toujours là
            merci pour ton aide.
            0
          2. j'ai télécharger le programme, instalé et lancé,j'ai refais une analyse avec norton et il est toujours là
            merci pour ton aide.
            0
          3. En utilisant le programme CleanUp voici se que j'ai concernant le trojan sur IE5.
            que faut t'il faire?
            merci d'avance.

            Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\ajout[1].php3 - deleted
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\affich-1449192[1] currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WPYRGDI7\AAMSZ=1X1[1] - deleted
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\OLK66\ - deleted
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\affich-1449192[1] currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\affich-1449192[1] currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\C3DVA23X\affich-1449192[1] currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
            C:\Documents and Settings\Patrick\Local Settings\Historique\History.IE5\MSHist012005043020050501\index.dat currently in use. Will be deleted w
            0
          4. Contributeur sécurité
            @patrickcela te dit que certain ont ete effacer et que les autres le seront au redemarrage de ton pc
            0
          5. @balltrap34je viens de refaire une analyse après avoir redémaré et norton le détecte toujours
            aurais- tu une autre solution?
            merci d'avance.
            0
        2. j'ai un trojan domcom qui est sur ipreg 32.dll, norton me renseigne le chemin suivant C:\windows\system 32\config\systemprofile\local settings\temporary internet file\content.IE5.
          quel est la procédure pour le retirer?
          d'avance merci.
          0
          1. De rien nat,

            Bon surf et bon week end ^^
            0
            1. coucou nathalie:

              Fais un nettoyage des fichiers temps...etc avec ce programme:
              http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

              puis supprime ce qui est en gras:

              C:\WINDOWS\system32\mpsys.exe
              C:\WINDOWS\system32\msfwe1.exe
              C:\WINDOWS\system32\SndMon16.exe

              Ensuite refais un scan chez RAV pour verification...
              ton probleme est il resolu?

              Bon courage
              0
              1. je n'arrive pas a trouver
                C:\WINDOWS\system32\SndMon16.exe

                j'ai supprimé les autrees mais celui-ci est introuvable

                merci
                0
              2. Merci beaucoup pour vos conseils,
                je suis arrivée à virer le fichier que j'arrrivais pas à trouver, j'ai fait de nouveau 1 RAV et je n'ai plus de virus

                Encore merci

                Nathalie
                0
            2. Contributeur sécurité
              pour les voir fait ceci
              Affiche tous les fichiers et dossiers :
              cliquer sur démarrer/panneau de configuration/option des dossiers/affichage
              Cocher afficher les dossiers cacher

              Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

              Décocher masquer les extensions dont le type est connu
              Puis fais «Ok» pour valider les changements.

              Et appliquer
              0
              1. bonjour moi aussi j'ai attrapé trojan domcom, j'ai lancer le scan sur raScan started at 30/04/2005 08:48:13

                Scanning memory...
                Scanning boot sectors...
                Scanning files...
                C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\OPQFG567\CAQZ6NYH.HTM - Exploit:HTML/MhtRedir.gen* -> Infected
                C:\WINDOWS\system32\mpsys.exe - TrojanDropper:Win32/Juntador.E -> Infected
                C:\WINDOWS\system32\msfwe1.exe - TrojanDropper:Win32/Small.QH -> Infected
                C:\WINDOWS\system32\SndMon16.exe - Worm:Win32/Wootbot -> Infected

                Scanned
                ============================
                Objects: 107796
                Directories: 4985
                Archives: 18122
                Size(Kb): 1136887
                Infected files: 4

                Found
                ============================
                Viruses found: 4
                Suspicious files: 0
                Disinfected files: 0
                Mail files: 600
                v et voila la réponse
                0
            3. Contributeur sécurité
              salut
              clik sur demarrer et sur rechercher ensuite tu clik sur tous les dossier et fichiers
              la tu copie colle ceci a tour de role et tu suppr se qui est en gras
              C:\WINDOWS\Temp\setup4002b.cab->u6f6uftuc_.exe
              C:\FOUND.000\FILE0048.CHK->u6f6uftuc_.exe
              C:\FOUND.000\FILE0058.CHK
              C:\FOUND.000\FILE0075.CHK

              0
              1. salut,
                supprime ce qui est en gras:
                C:\WINDOWS\Temp\setup4002b.cab->u6f6uftuc_.exe
                C:\FOUND.000\FILE0048.CHK->u6f6uftuc_.exe
                C:\FOUND.000\FILE0058.CHK
                C:\FOUND.000\FILE0075.CHK

                et refais scan pr verif

                a+
                0
                1. hello le probleme c'est que tout ce qui est c:/found000. je ne sais pas ou ils se trouvent meme en faisant rechercher.
                  Peux tu m'aider encore une fois

                  merci
                  0
                2. tu vas me dire que je suis nulle mais j'ai fais tout ce que tu m'as dis et il ne trouve pas l'emplacement des fichiers il me met aucun resultat a afficher. Je commence a desesperer

                  help
                  0
                3. je dois couper j'essaierai demain si j'ai encore des problemes je peux te contacter ?

                  Encore merci pour ton aide
                  0
                4. Contributeur sécurité
                  @sabineje serai pal la
                  mais les autres t aideront
                  a++
                  0
              2. j'ai fait un sur rav et voici une copie du rapport si ça peut aider pour un remede raScan started at 25/04/2005 19:50:50

                Scanning memory...
                Scanning boot sectors...
                Scanning files...
                C:\WINDOWS\Temp\setup4002b.cab->u6f6uftuc_.exe - Sahat.A -> Infected
                C:\FOUND.000\FILE0048.CHK->u6f6uftuc_.exe - Sahat.A -> Infected
                C:\FOUND.000\FILE0058.CHK - TrojanDownloader:Win32/IstBar.IJ -> Infected
                C:\FOUND.000\FILE0075.CHK - TrojanDownloader:Win32/IstBar.IJ -> Infected
                C:\FOUND.000\FILE0111.CHK - Sahat.A -> Infected

                Scanned
                ============================
                Objects: 20101
                Directories: 1110
                Archives: 4362
                Size(Kb): 960304
                Infected files: 5

                Found
                ============================
                Viruses found: 2
                Suspicious files: 0
                Disinfected files: 0dical
                0
                1. Salut,

                  j'ai herité du trojan.domcom dans un fichier ipreg32.dll as tu trouvé comment l'enlever car norton antivirus ne parvient pas a le supprimer.

                  Merci pour ton aide car je deviens dingue a ne pas y arriver
                  0
                  1. Contributeur sécurité
                    re
                    recherche et suppr le fichier
                    c:\windows\autoclk.exe
                    0
                    1. c:\windows\autoclk.exe-trojan:win32/killreg.d
                      0
                      1. c:\windows\autoclk.exe-trojan:win32/killreg.d
                        0
                        1. Contributeur sécurité
                          salut
                          il faudrai connaitre l emplacement exacte stp
                          0
                          • 1
                          • 2