|
|
|
|
Bonjour,
Après lecture de différents post , j'ai tenté de suivre "http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr" sans grand succès.
Impossible de lancer CCleaner. L'application se referme imédiatement après ouverture.
Impossible également de lancer de AVG Anti Spyware "Echec de la connexion au service. relancez l'install..." qu'il est d'ailleurs impossible de relancer...
J'avais préalablement désintaller Trend Micro 12 pour le remplacer par AVG qui avait trouvé des virus (pas log, désolé), mais pas tous puisque le pb persiste.
J'ai supprimé AVG pour tenter de ré-installer Trend micro 12 sans succès.
Maintenant, plus aucune appli de sécurité ne veux tourner !
Impossible d'installer hijackthis . la boite de dialogue se referme avant d'avoir choisi un répertoire d'instal...
Le seul truc que j'ai est le rapport bitdefender online scan:
Merci de votre aide.
Loopkinn
Statistics
Time
02:32:22
Files
229581
Folders
6163
Boot Sectors
3
Archives
6546
Packed Files
43481
Results
Identified Viruses
7
Infected Files
34
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
34
Engines Info
Virus Definitions
1411247
Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)
Scan plugins
16
Archive plugins
43
Unpack plugins
7
E-mail plugins
6
System plugins
5
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst=>[Subject: Mail server report.][From: secur@tjh.com]=>Update-KB7200-x86.zip=>Update-KB7200-x86.exe
Infected with: Win32.Warezov.GC@mm
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst=>[Subject: Mail server report.][From: secur@tjh.com]=>Update-KB7200-x86.zip=>Update-KB7200-x86.exe
Deleted
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst=>[Subject: Mail server report.][From: secur@tjh.com]=>Update-KB7200-x86.zip
Updated
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst
Updated
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst=>[Subject: Just You][From: Reynold]=>greeting card.exe
Infected with: Trojan.Downloader.Bai.DAM
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst=>[Subject: Just You][From: Reynold]=>greeting card.exe
Deleted
C:\Documents and Settings\Maryse\Local Settings\Application Data\Microsoft\Outlook\archive.pst
Updated
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\89SBCDWX\b64_1[1].jpg
Infected with: Backdoor.Hupigon.43213
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\89SBCDWX\b64_1[1].jpg
Deleted
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\89SBCDWX\b64_3[1].jpg
Infected with: Win32.Bagle.SUQ@mm
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\89SBCDWX\b64_3[1].jpg
Deleted
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\IF4VK929\b64_3[1].jpg
Infected with: Win32.Bagle.SUQ@mm
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\IF4VK929\b64_3[1].jpg
Deleted
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\QLGBK9YP\b64[1].jpg
Infected with: Win32.Bagle.SUQ@mm
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\QLGBK9YP\b64[1].jpg
Deleted
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\QLGBK9YP\b64_1[1].jpg
Infected with: Backdoor.Hupigon.43213
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\QLGBK9YP\b64_1[1].jpg
Deleted
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\SDIJ0LMF\b64_3[1].jpg
Infected with: Win32.Bagle.SUQ@mm
C:\Documents and Settings\Maryse\Local Settings\Temporary Internet Files\Content.IE5\SDIJ0LMF\b64_3[1].jpg
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114066.sys
Infected with: Rootkit.Bagle.F
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114066.sys
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114067.exe
Infected with: MemScan:Trojan.Downloader.Bagle.IW
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114067.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114072.sys
Infected with: Rootkit.Bagle.F
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114072.sys
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114081.exe
Infected with: MemScan:Trojan.Downloader.Bagle.IW
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114081.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114082.exe
Infected with: MemScan:Trojan.Downloader.Bagle.IW
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114082.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114088.sys
Infected with: Rootkit.Bagle.F
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114088.sys
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114093.exe
Infected with: Win32.Bagle.SUQ@mm
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114093.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114244.sys
Infected with: Rootkit.Bagle.F
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114244.sys
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114245.exe
Infected with: Win32.Bagle.SUQ@mm
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114245.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114246.exe
Infected with: Win32.Bagle.SUQ@mm
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0114246.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115255.sys
Infected with: Rootkit.Bagle.F
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115255.sys
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115256.exe
Infected with: Win32.Bagle.SUQ@mm
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115256.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115257.exe
Infected with: Win32.Bagle.SUQ@mm
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115257.exe
Deleted
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115258.exe
Infected with: MemScan:Trojan.Downloader.Bagle.IW
C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP744\A0115258.exe
Deleted
C:\WINDOWS\system32\drivers\downld\1017072.exe
Infected with: Win32.Bagle.SUQ@mm
C:\WINDOWS\system32\drivers\downld\1017072.exe
Deleted
C:\WINDOWS\system32\drivers\downld\101776.exe
Infected with: Win32.Bagle.SUQ@mm
C:\WINDOWS\system32\drivers\downld\101776.exe
Deleted
C:\WINDOWS\system32\drivers\downld\170865.exe
Infected with: Win32.Bagle.SVL@mm
C:\WINDOWS\system32\drivers\downld\170865.exe
Deleted
C:\WINDOWS\system32\drivers\downld\172147.exe
Infected with: Backdoor.Hupigon.43213
C:\WINDOWS\system32\drivers\downld\172147.exe
Deleted
C:\WINDOWS\system32\drivers\downld\190754.exe
Infected with: Win32.Bagle.SUQ@mm
C:\WINDOWS\system32\drivers\downld\190754.exe
Deleted
C:\WINDOWS\system32\drivers\downld\195210.exe
Infected with: Backdoor.Hupigon.43213
C:\WINDOWS\system32\drivers\downld\195210.exe
Deleted
C:\WINDOWS\system32\drivers\downld\210222.exe
Infected with: Win32.Bagle.SUQ@mm
C:\WINDOWS\system32\drivers\downld\210222.exe
Deleted
C:\WINDOWS\system32\drivers\downld\91932.exe
Infected with: Backdoor.Hupigon.43213
C:\WINDOWS\system32\drivers\downld\91932.exe
Deleted
C:\WINDOWS\system32\drivers\downld\985487.exe
Infected with: Backdoor.Hupigon.43213
C:\WINDOWS\system32\drivers\downld\985487.exe
Deleted
C:\WINDOWS\system32\drivers\downld\988371.exe
Infected with: Win32.Bagle.SUQ@mm
C:\WINDOWS\system32\drivers\downld\988371.exe
Deleted
C:\WINDOWS\system32\drivers\downld\99202.exe
Infected with: Win32.Bagle.SUQ@mm
C:\WINDOWS\system32\drivers\downld\99202.exe
Deleted
C:\WINDOWS\system32\drivers\downld\99743.exe
Infected with: Backdoor.Hupigon.43213
C:\WINDOWS\system32\drivers\downld\99743.exe
Deleted
Configuration: Windows XP Firefox 2.0.1
Salut,
|
Re,
|
Bien ...
|
Voilà le rapport ComboFix.
|
La suite :
|
La suite et peut-être la fin ? Loopkinn
|
Bien ... fais ce-ci dans l'ordre :
|
Le rapport HiJackThis: Loopkinn.
|
Bien ...
|
VirusTotal :
|
Note :
|
Bonne nuit à toi aussi ^^
|
Hello, voici le rapport MalwareBytes qui est vierge. Loopkinn
|
On continu avec le rapport HijackThis. Loopkinn
|
Salut,
|
SKe 69,
|