VIRUS VERS SUR MSN

bonjour,

sur msn, j ai accepte un fichier ; album photo...depuis, je suis infecte de 2 virus:

Backdoor.Win32.IRCBot.acd et JS/IstBar.l@dl..

merci de m'aider à les eliminer car mon antivirus les detecte mais ne les nettoie pas...

A tres bientot
Configuration: Windows XP
Internet Explorer 6.0

46 réponses

Résumé de la discussion

Une infection par deux virus survient après l'ouverture d'un fichier reçu sur MSN sur Windows XP avec Internet Explorer 6, à savoir Backdoor.Win32.IRCBot.acd et JS/IstBar.l@dl, détectés mais non nettoyés par l'antivirus. Plusieurs conseils proposent d'exécuter des outils de détection en mode sans échec, d'analyser un rapport HijackThis et d'éliminer les éléments suspects avec des utilitaires comme Navipromo ou MSNFix. Des rapports indiquent toutefois que certains résultats peuvent révéler des fichiers légitimes, d'où la prudence et la sauvegarde préalable avant toute suppression manuelle, et la vérification de chaque élément détecté par les outils.

Bobot (l’IA à votre service)
  1. salut,
    tu n'as pas coller le rapport clean ?
    J'aurai bien aimer le voir...
    merci..
    1. Bonjour,

      Salut philo mon ordi va mieux merci de ton aide

      bonne route

      a bientot peut etre !

      romuald
      1. salut philo,

        ci dessous le rapport...je commence à perdre espoir!!!!il y en a toujours!!!!lol

        Incident Status Location

        Potentially unwanted tool:Application/Pskill.K Not disinfected C:\Documents and Settings\HP_Propriétaire\Bureau\ANTIS VIRUS\clean.zip[clean/pskill.exe]
        Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\HP_Propriétaire\Bureau\ANTIS VIRUS\MSNFix\incl\Process.exe
        Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\HP_Propriétaire\Bureau\ANTIS VIRUS\SmitfraudFix\Process.exe
        Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\HP_Propriétaire\Bureau\ANTIS VIRUS\SmitfraudFix\Reboot.exe
        Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\HP_Propriétaire\Bureau\ANTIS VIRUS\SmitfraudFix\restart.exe
        Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\HP_Propriétaire\Bureau\ANTIS VIRUS\smitfraudfix.exe
        Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@apmebf[1].txt
        Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@bluestreak[2].txt
        Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@doubleclick[1].txt
        Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@xiti[1].txt
        Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
        Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Navilog1\Process.exe
        Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
        Virus:W32/MSNworm.L.worm Disinfected C:\WINDOWS\system32\LIBCINET.0XE
        Virus:W32/MSNworm.L.worm Disinfected C:\WINDOWS\system32\LIBWINETS.0LL
        Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
        1. Bonjour,

          VOICI LE RAPPORT SUITE F SECURE/

          Scanning Report
          Wednesday, October 03, 2007 14:11:46 - 16:59:21
          Computer name: DREAMLAND
          Scanning type: Scan system for viruses, rootkits, spyware
          Target: C:\ D:\

          --------------------------------------------------------------------------------

          Result: 13 malware found
          Tracking Cookie (spyware)
          System (Disinfected)
          System
          System
          System
          System
          System
          System
          System
          System
          System
          System
          System
          W32/Malware.AXAF (virus)
          C:\PROGRAM FILES\FICHIERS COMMUNS\JAVA\UPDATE\BASE IMAGES\JRE1.6.0.B105\PATCH-JRE1.6.0_02.B06\PATCHJRE.EXE (Submitted)

          --------------------------------------------------------------------------------

          Statistics
          Scanned:
          Files: 44592
          System: 6320
          Not scanned: 4
          Actions:
          Disinfected: 1
          Renamed: 0
          Deleted: 0
          None: 12
          Submitted: 1
          Files not scanned:
          C:\HIBERFIL.SYS
          C:\PAGEFILE.SYS
          C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
          C:\DOCUMENTS AND SETTINGS\HP_PROPRIɔAIRE\APPLICATION DATA\ISPNEWS\ISPN.INI

          --------------------------------------------------------------------------------

          Options
          Scanning engines:
          F-Secure Libra: 2.4.2, 2007-10-02
          F-Secure AVP: 7.0.171, 2007-10-03
          F-Secure Orion: 1.2.37, 2007-10-03
          F-Secure Blacklight: 1.0.64
          F-Secure Draco: 1.0.35, 2007-09-17
          F-Secure Pegasus: 1.19.0, 2007-09-01
          Scanning options:
          Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
          Use Advanced heuristics

          --------------------------------------------------------------------------------

          Copyright © 1998-2006 Product support |Send virus sample to F-Secure
          F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
          1. Bonjour,

            le rapport ne s'aafiche pas, ci dessous les quelques infos :

            Online Scanner a terminé.
            Un antiprogramme a été détecté (13) et votre ordinateur a été nettoyé.

            que dois je faire????

            merci
            1. ok,
              fais ceci:
              http://support.f-secure.fr/fra/home/ols.shtml
              avec Iexplorer
              postes le rapport
              1. Bonjour,

                Salut PHILO,

                Mon pc se comporte bien mais securitoo régulierement détecte les 2 virus et me dit qu il ne peut les nettoyés....
                Donc pour l instant pas de panique a bord mais une forte motivation pour dégager les intrus en question.

                ils doivent se nicher qq part mais ou?

                QQ UN A T IL DEJA REUSSI A ELIMINER CES 2 VIRUS ?

                A +
                1. Bonjour,
                  merci philo2100 je crois avoir reussit a enlever le virus msn enfin je croi seulemlent mais j'ai un autre probleme avec mon ordinateur et donc je l'ai mis sur fix 64#0
                  1. salut kaufman-cata,
                    refaits un nouveau post et récapitule ton soucis, tu peux insérer le lien direct ici, j'irais voir.
                    1. désole d'avoir interrompu votre conversation mais je penser que c'était à moi que PHILO 2100 donne cette information du coup j'ai fait Search Navipromo version 3.1.1 ,RAPPORT DU PROGRAMME HIJACKTHIS et MSNFix 1.515 peux tu me dire si cela va endommager mon PC et comment puis je faire enlever le virus de msn je ne peux plus y acceder.

                      Merci d'avance, désoler encore.
                      1. BONJOUR PHILO

                        VOICI LE RESULTAT...

                        Search Navipromo version 2.0.9 commencé le 25/09/2007 à 10:51:36,84

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Poster ce rapport sur le forum pour le faire analyser !!!
                        !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                        Fix lancé depuis C:\Program Files\navilog1
                        Mise a jour le 20.08.2007 a 22h30 by IL-MAFIOSO

                        Executé en mode normal

                        *** Recherche Programmes installes ***

                        *** Recherche dossiers dans C:\WINDOWS ***

                        *** Recherche dossiers dans C:\Program Files ***

                        *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                        *** Recherche dossiers dans C:\Documents and Settings\HP_Propri‚taire\Application Data ***

                        *** Recherche avec BlackLight Engine/F-secure ***
                        BlackLight Engine est un produit de F-secure, pour + d'infos :
                        https://www.f-secure.com/en

                        F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
                        ======================================

                        Copyright 2005-2006 F-Secure Corporation. All rights reserved.
                        This is a beta version. It will expire on 1st of October, 2007.
                        Version information: 2.2.1064.

                        [+] Started on 09/25/07 at 10:51:40.
                        [+] Initializing ...
                        [+] Starting scan, press Ctrl-C to abort.
                        [+] Scanning for hidden items .............................................................................
                        [+] Scan complete.
                        [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
                        [+] Exited on 09/25/07 at 10:57:49 (return code = 0).

                        *** Recherche avec GenericNaviSearch ***
                        !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                        !!! A verifier impérativement avant toute suppression manuelle !!!

                        Fichiers trouvés :

                        Aucun Fichier trouvé !

                        Fichiers suspects :

                        Aucun Fichier suspect trouvé !

                        *** Recherche fichiers ***

                        *** Recherche cles registre ***

                        Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

                        Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

                        Recherche Clé Magic Control

                        *** Module de Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche fichiers connus:

                        2)Recherche Heuristique :
                        *
                        **
                        ***
                        ****
                        *****
                        ******
                        *******
                        ********

                        3)Recherche Certificats :

                        Certificat Egroup absent !

                        *** Analyse Terminé le 25/09/2007 à 10:58:38,68 ***
                        1. philo

                          mon dernier rapport est en page 26 les autres ne sont pas de moi......

                          MERCI
                          1. salut philo

                            j ai constaté que "kaufmann cata "avait posté un rapport sur notre discussion !

                            alors je prefere avant de continuer m'assurer que les dernieres instruction me concernent bien moi!

                            merci de m'indiquer la marche a suivre apres le rapport que je t'ai posté suite a f secure ........

                            merci philo
                            1. voila merci de mavoir repondu
                              alors qu'est ce que je fais philo2100

                              Search Navipromo version 3.1.1 commencé le 22/09/2007 à 18:36:09,49

                              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                              !!! Poster ce rapport sur le forum pour le faire analyser !!!
                              !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                              Fix lancé depuis C:\Program Files\navilog1
                              Mise a jour le 21.09.2007 a 18h00 by IL-MAFIOSO

                              Microsoft Windows XP [version 5.1.2600]
                              Internet Explorer : 6.0.2800.1106

                              *** Recherche Programmes installes ***

                              *** Recherche dossiers dans C:\WINDOWS ***

                              *** Recherche dossiers dans C:\Program Files ***

                              *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                              *** Recherche dossiers dans C:\Documents and Settings\PHYLLIS\Application Data ***

                              *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                              *** Recherche avec BlackLight Engine/F-secure ***
                              BlackLight Engine est un produit de F-secure, pour + d'infos :
                              https://www.f-secure.com/en

                              F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
                              ======================================

                              Copyright 2005-2006 F-Secure Corporation. All rights reserved.
                              This is a beta version. It will expire on 1st of October, 2007.
                              Version information: 2.2.1064.

                              [+] Started on 09/22/07 at 18:36:16.
                              [+] Initializing ...
                              [+] Starting scan, press Ctrl-C to abort.
                              [+] Scanning for hidden items ....................................
                              [+] Scan complete.
                              [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
                              [+] Exited on 09/22/07 at 18:40:17 (return code = 0).

                              *** Recherche avec GenericNaviSearch ***
                              !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                              !!! A verifier impérativement avant toute suppression manuelle !!!

                              * Scan C:\WINDOWS\system32 *

                              * Scan C:\Documents and Settings\PHYLLIS\local settings\application data *

                              *** Recherche fichiers ***

                              *** Recherche cles registre ***

                              *** Module de Recherche complémentaire ***
                              (Recherche fichiers spécifiques)

                              1)Recherche fichiers connus:

                              2)Recherche Heuristique :

                              3)Recherche Certificats :

                              Certificat Egroup absent !

                              *** Analyse Terminé le 22/09/2007 à 18:40:49,92 ***
                              • 1
                              • 2
                              • 3