virus

Section d'analyse de rapports et de désinfection : malwares en tous genre et autres indésirables. Demandes de nettoyage uniquement. Prise en charge restreinte : équipe spécialisée.

Modérateur: Modérateurs

Règles du forum :arrow: Les désinfections sont prises en charge par un groupe spécifique, tout le monde ne peut pas intervenir pour désinfecter les machines (règles).
:arrow: Les procédures sont sur-mesure, ne faites pas la même chose chez vous (explications).
:arrow: Un topic par machine, chacun crée le sien. ;)

virus

Messagepar legrand » 21 Aoû 2009 20:35

j'ai demarer en mode sans echec et reussit a mettre en route malwarebytes il a trouver 130 chose a enlever bon sa remarche.voici le rapport quand meme.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:34:14, on 21/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\WINDOWS\vVX3000.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRAM FILES\CAERE\OMNIPAGEPRO90\opware32.exe
C:\windows\system32\ntvdm.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Creative\Launcher\CTLauncher.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\OpenOffice\program\soffice.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Installer\MSI132.tmp
C:\windows\system32\svchost.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\winamp.exe
C:\windows\system32\faclayt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\windows\System32\svchost.exe
C:\windows\TEMP\sdr5.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=488
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OmniPage] C:\PROGRAM FILES\CAERE\OMNIPAGEPRO90\opware32.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Regedit32] C:\windows\system32\regedit.exe
O4 - HKLM\..\Run: [Winamp Agent] C:\windows\system32\winamp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Administrateur] C:\Documents and Settings\Administrateur\Administrateur.exe /i
O4 - HKUS\S-1-5-18\..\Run: [] C:\Documents and Settings\LocalService.AUTORITE NT\.exe /i (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [LocalService] C:\Documents and Settings\LocalService.AUTORITE NT\LocalService.AUTORITE NT.exe /i (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\Documents and Settings\LocalService.AUTORITE NT\.exe /i (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Program Files\OpenOffice\program\quickstart.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [java_sun] Java (Sun)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 5358007468
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5357998890
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O20 - Winlogon Notify: bgeunqd - bgeunqd.dll (file missing)
O20 - Winlogon Notify: csbdll - C:\windows\SYSTEM32\csbdll.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: SolidConverterPDFv4ReadSpool (SCPDFV4ReadSpool) - Solid Documents, LLC - C:\WINDOWS\Installer\MSI132.tmp

--
End of file - 9104 bytes
legrand
 
Messages: 37
Inscription: 24 Avr 2009 23:11

Re: virus

Messagepar nardino » 21 Aoû 2009 20:40

Bonsoir.
Pas de trace d'antivirus ni de pare-feu dans ton rapport.
As-tu une explication à cette absence ?
Peux-tu poster le dernier rapport d'analyse de Malwarrbytes'Anti-Malware ?

Télécharge Antivir Free d'Avira
http://dl1.avgate.net/down/windows/anti ... u_fr_h.exe

Clique sur fichier antivir_workstation_winu_fr_h.exe pour l'installer.
Mets-le à jour.
Dans Configuration, coche Mode Expert en haut à gauche.
Clique sur Scanner, sur Recherche et sur Actions en cas de résultat positif.
Dans la partie droite coche Automatique et Copier le fichier dans la quarantaine avant l'action.
Dans Action principale avec le menu par la flèche choisis réparer
Dans Action secondaire renommer.
Tu valides tout ces choix par OK.
Tu cliques sur l'icône du bureau pour le lancer ou sur celle près de l'horloge.
A gauche dans Aperçu > Etat, tu cliques sur Contrôler syst.maintenant.
L'analyse peut durée une heure ou plus selon la taille de tes données.
Quand la barre de progression sera à 100% tu cliques sur Rapport.
Tu fais un copier-coller de la totalité dans ta réponse puis tu le fermes et tu cliques sur Arrêter.
Tu le retrouveras dans Aperçu > Rapports > Recherche avec la date correspondante.
Double-clique dessus et ensuite sur Rapport pour l'ouvrir.

Rappel pour copier coller:
CTRL+A pour tout sélectionner
CTRL+C pour copier
CTRL+V pour coller dans la réponse
@+
Image
Avatar de l’utilisateur
nardino
Super Libellulien
Super Libellulien
 
Messages: 1100
Inscription: 03 Avr 2009 22:02

Re: virus

Messagepar nardino » 21 Aoû 2009 20:46

Bonsoir.
Je viens de constater que tu avais déjà ouvert un autre sujet.
Il eut été préférable de continuer dessus.
Fermes-le si tu continues ici.
@+
Image
Avatar de l’utilisateur
nardino
Super Libellulien
Super Libellulien
 
Messages: 1100
Inscription: 03 Avr 2009 22:02

Re: virus

Messagepar legrand » 23 Aoû 2009 20:01

oui je vais essayer de fermer l'autre sujet je ne savait pas qu'il fallait continuer sur le meme j'ai fait une analyse:Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2551
Windows 5.1.2600 Service Pack 3

23/08/2009 20:52:21
mbam-log-2009-08-23 (20-52-21).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 199252
Temps écoulé: 31 minute(s), 35 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 155

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065693.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065694.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065854.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065843.scr (Backdoor.Sdbot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065927.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065928.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065929.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065930.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065931.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065932.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065933.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065935.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP184\A0065936.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0065957.exe (Backdoor.SdBot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0065958.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066982.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066983.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066984.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066985.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066986.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066987.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066988.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066989.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066990.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066991.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066992.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066993.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066994.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066995.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066997.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066998.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066999.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067000.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067001.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067002.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067003.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067004.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067005.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067006.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067007.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067008.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067009.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067010.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067011.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067012.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067013.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067015.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067016.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067017.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067018.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067019.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067020.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067021.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067022.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067023.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067024.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067025.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067026.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067027.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067028.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0066996.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP185\A0067014.scr (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0068765.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0068971.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069000.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069016.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069063.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069142.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069151.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069180.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069197.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069227.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069258.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069275.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069284.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069370.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0070404.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0070438.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0070499.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0070532.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0069379.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0070490.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP186\A0070508.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0070619.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0070630.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0071776.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0071785.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0071920.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0071969.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072008.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072037.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072056.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072136.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072085.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072174.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072221.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP187\A0072252.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP188\A0072262.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP188\A0072300.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP188\A0072335.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP188\A0072350.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP188\A0072270.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP188\A0072359.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072387.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072403.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072404.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072407.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072417.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072428.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072429.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072439.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072468.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072477.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072415.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072613.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072527.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072535.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072567.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072584.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072651.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072668.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072699.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0072739.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP189\A0073466.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075138.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075180.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075211.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075249.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075269.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075305.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075359.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075349.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075409.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075417.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075426.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075492.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075615.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075620.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075621.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075622.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075623.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075624.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075625.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075626.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075627.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075628.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075629.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075630.scr (Trojan.Spambot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075631.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075632.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075633.exe (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075634.exe (Backdoor.SdBot) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075635.exe (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075636.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9FDC9274-F8F1-461D-AA3B-ACB518ABAD2A}\RP190\A0075647.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
legrand
 
Messages: 37
Inscription: 24 Avr 2009 23:11

Re: virus

Messagepar nardino » 24 Aoû 2009 11:46

Bonjour.

Rien de grave car tous les fichiers détectés par Malwarebytes'Anti-Malware se trouvent dans des points de restauration et ne seront donc activés que dans le cas d'utilisation de ces points.
Pour purger la source définitivement, tu désactives la resauration système et tu la résactives ensuite pour recréer un point sain.
Voici un tuto d'un autre forum je ne sais pas si il en existe un sur Libellules.com.
http://forum.pcastuces.com/desactiver_l ... -f31s7.htm
Fais quand même un sca Antivir comme demandé plus haut.
@+

Edit.
Voici le tuto maison
http://www.libellules.ch/desactiver_restauration.php :mrgreen:
@+
Image
Avatar de l’utilisateur
nardino
Super Libellulien
Super Libellulien
 
Messages: 1100
Inscription: 03 Avr 2009 22:02


Retourner vers Désinfections et demandes d'analyse

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 5 invités
cron