Mon PC est attaqué par trojan: cheval de troi

Fermé
oranais2007 Messages postés 24 Date d'inscription mardi 12 février 2008 Statut Membre Dernière intervention 16 juin 2009 - 13 févr. 2008 à 22:15
 Utilisateur anonyme - 7 mars 2008 à 15:41
Bonsoir DIID,je t'envoi le rapport d'analyse de SDFix:


SDFix: Version 1.141

Run by user on 08/02/2008 at 18:54

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Program Files\Helper\1167680104.dll - Deleted
C:\Program Files\Helper\1167680120.dll - Deleted
C:\WINDOWS\system32\regscan.exe - Deleted



Folder C:\Program Files\Helper - Removed
Folder C:\Program Files\Sotfone - Removed


Removing Temp Files...

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-08 19:02:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpoli cy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enable d:@xpsp2res.dll,-22019"
"C:\\Program Files\\Global Star Software\\Airport Tycoon 3\\at3.exe"="C:\\Program Files\\Global Star Software\\Airport Tycoon 3\\at3.exe:*:Enabled:at3"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"="C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe:*:Enabled:VoipBuster"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Documents and Settings\\user\\Bureau\\Nouveau dossier (2)\\MiniRacer\\engine.exe"="C:\\Documents and Settings\\user\\Bureau\\Nouveau dossier (2)\\MiniRacer\\engine.exe:*:Enabled:engine"
"C:\\Sierra\\SWAT3\\Swat.icd"="C:\\Sierra\\SWAT3\\Swat.icd:*:Enabled:File Packager"
"C:\\Program Files\\NetAppel\\NetAppel.exe"="C:\\Program Files\\NetAppel\\NetAppel.exe:*:Enabled:NetAppel"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe: *:Disabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\RocketRacer\\RocketRacer.exe"="C:\\Program Files\\RocketRacer\\RocketRacer.exe:*:Enabled:RocketRacer"
"C:\\Program Files\\Activision Value\\Secret Service Security Breach\\run.exe"="C:\\Program Files\\Activision Value\\Secret Service Security Breach\\run.exe:*:Enabled:run"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.0"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe: *:Disabled:Ex‚cuter une DLL en tant qu'application"
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\WINDOWS\\system32\\regscan.exe"="C:\\WINDOWS\\system32\\regscan.exe:*: Disabled:Microsoft(C) Registry Scaner"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpoli cy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enable d:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.0"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Mon 4 Feb 2008 395 A..H. --- "C:\Program Files\InterActual\InterActual Player\itiA7.tmp"
Fri 8 Feb 2008 1,202,416 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\02139d7491c2472e519aa5fd671932e9\BIT1B.tmp& quot;
Thu 7 Feb 2008 152,359 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\06610cab6d433e28e3786b6f4f2daf47\BIT2D.tmp& quot;
Thu 7 Feb 2008 907,008 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\08144e57132f3a3a58bb4806c267d6d1\BIT50.tmp& quot;
Thu 7 Feb 2008 152,546 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\098219b4e8f2ef50f602517142a31237\BIT26.tmp& quot;
Thu 7 Feb 2008 496,880 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0bec671f7dc8f7748a1ffde5cf338e6f\BIT27.tmp& quot;
Thu 7 Feb 2008 153,450 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0ff9f5f256e7b08831d696a6685c195f\BIT3A.tmp& quot;
Thu 7 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1809c92323cd35ff507e52ac617d468c\BIT4E.tmp& quot;
Thu 7 Feb 2008 152,411 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1814e080f0918d875bc3c2e921e10970\BIT44.tmp& quot;
Thu 7 Feb 2008 496,880 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\184e9e50ae9fd7c95e99fc939967f16c\BIT2E.tmp& quot;
Thu 7 Feb 2008 157,145 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1c2306aaf515d79b143e70a059dcb005\BIT2F.tmp& quot;
Thu 7 Feb 2008 7,531,128 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\249236e184433b685b8d328e2f3512f9\BIT5A.tmp& quot;
Thu 7 Feb 2008 150,705 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2f1e0b2e7849f3e4f9d5d467db620154\BIT38.tmp& quot;
Thu 7 Feb 2008 103,611 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3029b2f29f64280b034728bd3ef59e88\BIT4A.tmp& quot;
Thu 7 Feb 2008 154,851 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\316c5ef5d3baab1d970ac57655b7795e\BIT41.tmp& quot;
Thu 7 Feb 2008 102,648 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3e1bc779f4619c0546c190388ad30ab7\BIT30.tmp& quot;
Thu 7 Feb 2008 2,306,976 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3eea06b815b64a1ec7d25c94d62f9f47\BIT20.tmp& quot;
Fri 8 Feb 2008 152,165 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\428620248e6acbe62e21f802c0bdde51\BIT13.tmp& quot;
Thu 7 Feb 2008 156,293 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\43df8b7bf80c52c977ed884e53425972\BIT4B.tmp& quot;
Thu 7 Feb 2008 5,652,328 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4982a61e2216973813f44f56425bf3d9\BIT34.tmp& quot;
Fri 8 Feb 2008 484,080 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4c71ce3b86ebd63636c27412cf258102\BIT7.tmp&q uot;
Thu 7 Feb 2008 152,663 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\56d569c8405ec26ff4452dcba2879a6c\BIT3D.tmp& quot;
Thu 7 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5c6b46191661d86eff922cf2abc5383c\BIT2C.tmp& quot;
Fri 8 Feb 2008 706,954 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\62aacbbed083d147bc260148d9c15a82\BIT11.tmp& quot;
Thu 7 Feb 2008 154,448 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\63d24d8d47da118138382ddd3268b368\BIT52.tmp& quot;
Thu 7 Feb 2008 99,887 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\656c92fcd66b00f9a3fa9acad9d3bf1a\BIT5C.tmp& quot;
Thu 7 Feb 2008 2,174,016 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\681a621201432e2370333f0a3e14b97b\BIT42.tmp& quot;
Thu 7 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\699e24e86f6415432011025cecec293a\BIT2A.tmp& quot;
Thu 7 Feb 2008 618,760 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6c89685d74f58c2243a264acd492eb81\BIT48.tmp& quot;
Thu 7 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6d5b5febb5f05d8a6e9467711dc1f17b\BIT4D.tmp& quot;
Thu 7 Feb 2008 337,128 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6f6765898b516d5c60ff46b4dd07b9bb\BIT1D.tmp& quot;
Fri 8 Feb 2008 2,397,600 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\73858e237bdbfb285372b3c3e579c301\BIT8.tmp&q uot;
Thu 7 Feb 2008 497,392 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\73b47da4c089449773631e6d0dfe9592\BIT36.tmp& quot;
Thu 7 Feb 2008 522,480 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\73ce0aa3ab20205e92fd1d7b99bdba2d\BIT45.tmp& quot;
Thu 7 Feb 2008 483,568 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\74e9f428b65f24096f98956842c7b924\BIT3F.tmp& quot;
Thu 7 Feb 2008 3,118,632 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\754042b8f18f53e014ef41dc09e59b25\BIT5B.tmp& quot;
Thu 7 Feb 2008 105,941 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\794f891ee88c7bba8b5135dcddb15cc4\BIT43.tmp& quot;
Thu 7 Feb 2008 103,019 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\7ca53020d9647947d101c1afa84ceb6b\BIT56.tmp& quot;
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8f3e004a562e1247e8b254b9e4fee21c\BIT3.tmp&q uot;
Thu 7 Feb 2008 496,880 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\95fd4748e09823949a480f46a1d6e744\BIT55.tmp& quot;
Thu 7 Feb 2008 155,904 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9830744d4d1dc6aface2b642e58762d0\BIT35.tmp& quot;
Thu 7 Feb 2008 102,759 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9c112f9fe737a2dbcc7e8bb2c8d04126\BIT4C.tmp& quot;
Fri 8 Feb 2008 221,200 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9e24d26f8fcc7c984a0447571ea03d41\BIT6.tmp&q uot;
Thu 7 Feb 2008 343,784 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9fc9db2b14f84a4407c2eebb504e6ed1\BIT2B.tmp& quot;
Thu 7 Feb 2008 152,485 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a25ae7f568279d7634ac04e37b47fbbb\BIT31.tmp& quot;
Thu 7 Feb 2008 158,812 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a97bd412ef78c20b97d5d1e3965f7491\BIT57.tmp& quot;
Thu 7 Feb 2008 122,180 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad426d72cf1fc12ace56a2ebdd2ac923\BIT37.tmp& quot;
Thu 7 Feb 2008 338,152 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b437c563a57eb239b9adbb6181d9e57b\BIT59.tmp& quot;
Thu 7 Feb 2008 156,311 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b4e36ed2c9cf1a2608125d0f62467888\BIT23.tmp& quot;
Thu 7 Feb 2008 153,432 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b7a39c6d6693d1f3598adcd01ab559a0\BIT25.tmp& quot;
Fri 8 Feb 2008 398,568 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\bc2f519e2d2ae6ba0ff041c37deb44b0\BITB.tmp&q uot;
Thu 7 Feb 2008 902,384 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\bfb658f079266514691301bd85c44ba3\BIT3B.tmp& quot;
Thu 7 Feb 2008 103,553 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c3073a17bc1dad3634ef2a92953cadd0\BIT1E.tmp& quot;
Thu 7 Feb 2008 104,552 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c759407fceb9149391389903edb961ba\BIT47.tmp& quot;
Thu 7 Feb 2008 490,224 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c7d27c0cac59f65a716d84767ae303e8\BIT32.tmp& quot;
Thu 7 Feb 2008 883,592 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ca88d0ccb4f9f7b578334e02bd45e385\BIT54.tmp& quot;
Thu 7 Feb 2008 150,525 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cb00d23164ddebc356e6b72e735402cd\BIT4F.tmp& quot;
Thu 7 Feb 2008 156,867 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cc0dcdff9ecf4bee0a8ff8d3fea71393\BIT24.tmp& quot;
Thu 7 Feb 2008 103,201 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d05de61e582a01d1969c7442eab9add6\BIT3C.tmp& quot;
Thu 7 Feb 2008 497,904 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d06e30240208f2ced9c1bc80c13d10bb\BIT53.tmp& quot;
Thu 7 Feb 2008 103,333 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d0dead6218b777b0debc2e988b723b70\BIT39.tmp& quot;
Thu 7 Feb 2008 159,135 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d6e4726c24bd7b5cec32dc9a2f2939fd\BIT58.tmp& quot;
Thu 7 Feb 2008 151,443 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d930089a764f6749fced5083f1cf8bfd\BIT51.tmp& quot;
Thu 7 Feb 2008 156,315 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\da154a07f5b15d08bf1eed1b69d9c67b\BIT33.tmp& quot;
Thu 7 Feb 2008 153,204 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\dc26aa093cda188e55518398937b3343\BIT21.tmp& quot;
Thu 7 Feb 2008 338,152 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\dd3930b21d4f05031161cdaf2f7e6ff7\BIT46.tmp& quot;
Fri 8 Feb 2008 489,712 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\dedd59f165d16967c81b4410c77412ff\BIT1C.tmp& quot;
Fri 8 Feb 2008 151,723 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e9b4412c85c518de10acd6510fd185b6\BIT18.tmp& quot;
Thu 7 Feb 2008 569,656 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\eff5ee5469e17d1675b5e8783dd9c6af\BIT3E.tmp& quot;
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa05ce486c79c4fc88f5151036d658e0\BIT2.tmp&q uot;
Thu 7 Feb 2008 151,539 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fc4435e0f8f00166afca314c45417b4f\BIT28.tmp& quot;
Thu 7 Feb 2008 804,256 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0230a3590a31d668e4316ed3806e63\BIT49.tmp& quot;
Thu 7 Feb 2008 31,269 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fdd078ab7048ce05b739fa4c51137174\BIT40.tmp& quot;
Fri 8 Feb 2008 159,200 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1bbb1f27ee635690e1a4e27eb699c00a\download\B IT61.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2e97cbe532c7ab71623b16df846afc0d\download\B IT11.tmp"
Fri 8 Feb 2008 5,545,521 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3a0758370e23ff8b94b04b1e0032c776\download\B IT60.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3fc4c48da845525f8f6c17a5f84323c2\download\B ITF.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\407b292e00966e935360043354c0d71d\download\B ITD.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5bfc2df566e0403671b1abf7e607c521\download\B IT7A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5cd7b847b0d1fab05b4a625f201e9ec8\download\B ITB.tmp"
Fri 8 Feb 2008 147,572 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\716405ec081666b9edb4af2eb76573eb\download\B IT63.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\7e4fb765b942cac7dd07155373624500\download\B IT10.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\991b431aaac91158a60549d9003044fd\download\B IT7B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9ba9675594796c70a279084c24cd7675\download\B ITA.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a0141e73bbc406d3a6adf116f2c9aae1\download\B IT12.tmp"
Fri 8 Feb 2008 610,618 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b5ee865d9bc72aefa5f4912b7b36adcb\download\B IT7D.tmp"
Fri 8 Feb 2008 82,502 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c3af23dcfc6cdc694c9494a110401ffb\download\B IT7C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c6d0664b5cb57acdd9d704dd95c94a25\download\B ITC.tmp"
Fri 8 Feb 2008 1,286,444 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ca96cb0b825e3f78995921ac4c35ca18\download\B IT79.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7603a234845ad827178d60ca9b489ef\download\B ITE.tmp"
Fri 8 Feb 2008 630,618 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f99846289ec5950c569069bbd41e4c8f\download\B IT6B.tmp"
Thu 24 Aug 2006 107,008 A..H. --- "C:\Documents and Settings\user\Mes documents\lettres de motivation\chakib important\Nouveau dossier\~WRL2288.tmp"
Tue 13 Feb 2007 146,432 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL0401.tmp"
Tue 13 Feb 2007 148,480 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL0722.tmp"
Tue 13 Feb 2007 142,336 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL2077.tmp"
Tue 13 Feb 2007 147,968 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL2243.tmp"
Tue 13 Feb 2007 145,408 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL2624.tmp"
Tue 13 Feb 2007 145,408 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL2982.tmp"
Tue 13 Feb 2007 147,968 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL3156.tmp"
Tue 13 Feb 2007 145,408 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL3174.tmp"
Tue 13 Feb 2007 141,824 A..H. --- "C:\Documents and Settings\user\Mes documents\Cours\cours de pharmacie\TP QMPS\TP Gal‚nique\~WRL4000.tmp"

Finished!








Par contre,pour le Cleaner,j'ai pas eu de rapport!! dès qu'il se lance,il disparait!! c'est normal!!

mais malgres tout ça,le virus est toujour là!! car il ya dans la barre des tâches en dessous à droite une icône indiquant un dannger de virus mais c'est un irus en lui-même;



STP,je voudrai bien me débarasser de ces virus,


Merci.4 message(s) posté(s) depuis le mardi 12 février 2008
A voir également:

22 réponses

oranais2007 Messages postés 24 Date d'inscription mardi 12 février 2008 Statut Membre Dernière intervention 16 juin 2009
7 mars 2008 à 15:18
slt DIID,ça va?j'éspère que tu m'as pas encore oublié!!

j'attend ton msg;

slt
0
Utilisateur anonyme
7 mars 2008 à 15:41
Salut,
non mais....

Arff :
> Lance Hijackthis :
- Puis sélectionne < Scan >
- Coche les cases des lignes suivantes :

R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)

Ensuite,
- Ferme toutes les autres fenêtres et applications (même internet)
- Clic sur < fixe checked >

> Passe un coup de Ccleaner en mode sans échec stp

> Relance ton PC en mode normal puis Hijackthis :
Puis sélectionne < do a system scan and save a logfile >,

Et envoie, par collier/coller, ton log Hijackthis stp,

Après,
> Télécharge MalwareByte's Anti-Malware : http://www.malwarebytes.org/mbam/program/mbam-setup.exe
- Installe le programme puis lance le stp.
NB : S'il te manque COMCTL32.OCX alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/
- Fais les mises à jour (clique sur "Updates" puis "check for updates")
- Démarre en mode sans échec (image). Si problème : tuto ici
- Lance le MalwareByte's Anti-Malware puis clique sur "perform full scan" puis "scan" et sélectionne tous tes disques durs => le scan débute....patiente...
- A la fin clique sur clique "Remove Selected" (Si des éléments très difficiles à supprimer, un message te demandera de rédémarrer : clique sur "yes" alors)
- Un rapport va être généré : sauvegarde le et poste le sur forum stp.

A+
0