delf'anita
Messages postés3Date d'inscriptionmercredi 16 janvier 2008StatutMembreDernière intervention16 janvier 2008
-
16 janv. 2008 à 17:45
roxypoupette
Messages postés620Date d'inscriptionjeudi 27 décembre 2007StatutMembreDernière intervention23 septembre 2017
-
16 janv. 2008 à 17:47
Bonjour,
Bonjour,Bref, pour résumer, j'ai malencontreusement ouvert le satané fichier DSC01497.zip et dans les 5 secondes qui ont suivi je me suis aperçue que c'était un virus. j'ai réagi de suite et fermé MSN. J'ai même supprimer TOUT MSN avec clé de registre, dossier de partage etc... J'ai recherché le fichier infecté, supprimer de suite. Il n'est plus dans mon PC.
Bref 36h plus tard et après maintes et maintes recherches, passages de bitdefender, adaware (rien trouvé), ccleaner, spybot (rien trouvé) et msnfix et quelques sauvegardes de fichiers... Il ne me reste plus qu'à faire hidjackthis... c'est fait !! rapport en fin de post
J'ai presque tout compris mais je demande assistance pour être sûre de bien faire dans l'ordre (il serait temps car j'ai déja fait plein de trucs) ;o)
Bitdefender me trouve un virus trojan.peed.gen dans c\windows\system32\dllcache\spoolms.exe qui ne peut être effacé et que MSNfix ne trouve pas
Bitdefender me trouve plein de messages infestés dans le dossier junk de Thunderbird. (c'est vrai que j'ai un soucis de stockage depuis quelques semaines... je voulais le supprimer après avoir exporté mes carnets d'adresse mais fichier de désinstallation introuvable 'm^me avec Ccleaner). Je n'ose le virer à la sauvage en supprimant directement les dossiers. A votre avis ?
ATTENTION de peur que Spoolms.exe ne fasse des dégats, j'ai interrompu son processus dans le gestionnaire de fichier
MSNfix me dit que je suis infectée mais je ne trouve rien dans son rapport
MSNFix 1.629
C:\msnfix\MSNFix
Fix exécuté le 16/01/2008 - 7:16:55,39 By Administrateur mode normal
************************ Recherche les fichiers présents
... C:\WINDOWS\DSC01497.zip
************************ MSNCHK ***** /!\ beta test /!\
************************ Recherche les dossiers présents
... C:\Temp\
************************ Suppression des fichiers
.. OK ... C:\WINDOWS\DSC01497.zip
************************ Suppression des dossiers
.. OK ... C:\Temp\
************************ Nettoyage du registre
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 16012008_ 8005389.zip
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/ ------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
1- Le tout premier rapport de Bitdefender m'indiquait
Scanned File
Status
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 755)=>[Subject: ][Date: Tue, 01 Nov 2005 09:01:40 -0600]=>(MIME part)=>Info_prices.zip=>1.exe
Infected with: Win32.Bagle.EI@mm
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 755)=>[Subject: ][Date: Tue, 01 Nov 2005 09:01:40 -0600]=>(MIME part)=>Info_prices.zip=>1.exe
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 755)=>[Subject: ][Date: Tue, 01 Nov 2005 09:01:40 -0600]=>(MIME part)=>Info_prices.zip
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 755)=>[Subject: ][Date: Tue, 01 Nov 2005 09:01:40 -0600]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 755)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1004)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Tue, 22 Nov 2005 21:53:31 +0100]=>(MIME part)=>(MIME part)=>(message body)
Infected with: Exploit.Iframe.Vulnerability.B
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1004)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Tue, 22 Nov 2005 21:53:31 +0100]=>(MIME part)=>(MIME part)=>(message body)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1004)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Tue, 22 Nov 2005 21:53:31 +0100]=>(MIME part)=>(MIME part)=>(message body)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1004)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Tue, 22 Nov 2005 21:53:31 +0100]=>(MIME part)=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1004)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Tue, 22 Nov 2005 21:53:31 +0100]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1004)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1095)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Fri, 25 Nov 2005 18:17:27 +0100]=>(MIME part)=>(MIME part)=>(message body)
Infected with: Exploit.Iframe.Vulnerability.B
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1095)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Fri, 25 Nov 2005 18:17:27 +0100]=>(MIME part)=>(MIME part)=>(message body)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1095)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Fri, 25 Nov 2005 18:17:27 +0100]=>(MIME part)=>(MIME part)=>(message body)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1095)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Fri, 25 Nov 2005 18:17:27 +0100]=>(MIME part)=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1095)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Fri, 25 Nov 2005 18:17:27 +0100]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1095)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1097)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Sat, 26 Nov 2005 09:28:37 +0100]=>(MIME part)=>(MIME part)=>(message body)
Infected with: Exploit.Iframe.Vulnerability.B
Disinfection failed
Deleted
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1097)=>[Subject: [avast! - INFECTED] Mail Delivery (f][Date: Sat, 26 Nov 2005 09:28:37 +0100]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1097)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1727)=>[Subject: Registration Confirmation][Date: Thu, 29 Dec 2005 14:36:52 GMT]=>(MIME part)=>reg_pass-data.zip
Infected with: Win32.Sober.Y@mm
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1727)=>[Subject: Registration Confirmation][Date: Thu, 29 Dec 2005 14:36:52 GMT]=>(MIME part)=>reg_pass-data.zip
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1727)=>[Subject: Registration Confirmation][Date: Thu, 29 Dec 2005 14:36:52 GMT]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1727)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1778)=>[Subject: Registration Confirmation][Date: Mon, 02 Jan 2006 15:48:46 GMT]=>(MIME part)=>reg_pass-data.zip
Infected with: Win32.Sober.Y@mm
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1778)=>[Subject: Registration Confirmation][Date: Mon, 02 Jan 2006 15:48:46 GMT]=>(MIME part)=>reg_pass-data.zip
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1778)=>[Subject: Registration Confirmation][Date: Mon, 02 Jan 2006 15:48:46 GMT]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1778)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1799)=>[Subject: Registration Confirmation][Date: Tue, 03 Jan 2006 11:43:56 GMT]=>(MIME part)=>reg_pass.zip
Infected with: Win32.Sober.Y@mm
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1799)=>[Subject: Registration Confirmation][Date: Tue, 03 Jan 2006 11:43:56 GMT]=>(MIME part)=>reg_pass.zip
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1799)=>[Subject: Registration Confirmation][Date: Tue, 03 Jan 2006 11:43:56 GMT]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 1799)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 6245)=>[Subject: =?iso-8859-1?Q?Message_infect=E9_:_Fw:][Date: 23 Jun 2006 21:15:45 -0000]=>(MIME part)=>Attachments001.BHX
Infected with: Win32.Nyxem.E@mm
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 6245)=>[Subject: =?iso-8859-1?Q?Message_infect=E9_:_Fw:][Date: 23 Jun 2006 21:15:45 -0000]=>(MIME part)=>Attachments001.BHX
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 6245)=>[Subject: =?iso-8859-1?Q?Message_infect=E9_:_Fw:][Date: 23 Jun 2006 21:15:45 -0000]=>(MIME part)=>Attachments001.BHX
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 6245)=>[Subject: =?iso-8859-1?Q?Message_infect=E9_:_Fw:][Date: 23 Jun 2006 21:15:45 -0000]=>(MIME part)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox=>(message 6245)
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Inbox
Updated
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1032)
Infected with: Generic.Peed.Eml.21B44D2A
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1032)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1032)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1069)
Infected with: Generic.Peed.Eml.5637D621
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1069)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1069)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1123)
Infected with: Generic.Peed.Eml.6D67AF8A
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1123)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1123)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1217)
Infected with: Generic.Peed.Eml.09934ADC
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1217)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1217)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1219)
Infected with: Generic.Peed.Eml.1D7AB768
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1219)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1219)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1403)
Infected with: Generic.Peed.Eml.05B8BA46
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1403)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1403)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1947)
Infected with: Generic.Peed.Eml.A3F0A6C8
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1947)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1947)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1966)
Infected with: Generic.Peed.Eml.1BD36286
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1966)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 1966)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 2114)
Infected with: Generic.Peed.Eml.68D67772
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 2114)
Disinfection failed
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk=>(message 2114)
Deleted
C:\Documents and Settings\Administrateur\Application Data\Thunderbird\Profiles\dn66bezh.default\Mail\Local Folders\Junk
Update failed
Logfile of HijackThis v1.99.1
Scan saved at 09:22:13, on 16/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program
Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program
Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF
- res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF
existant - res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -