

ltdpt
Membres-
Compteur de contenus
20 -
Inscription
-
Dernière visite
ltdpt's Achievements

Junior Member (3/12)
0
Réputation sur la communauté
-
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Je m'en suis rendu compte, mais j'avais déjà posté (l'angoisse des novices, je suppose). Soigne bien cette grippe, et encore, du fond du coeur, merci. Et on sait jamais, peut être que j'aurais encore besoin d'aide -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Encore merci pour ton aide. Comme je n'avais pas de tes nouvelles, et que mon pc a commencé à me faire écran bleu sur écran bleu cet AM, et que ça commençait à m'inquiéter (alors que je l'avais dépoussiéré dans les règles de l'art cet AM, avec une jolie bombe à air et tout et tout - l'ingrat !!!), je me suis tourné vers pcentraide.com, et on a bien avancé dans la désinfection et le rétablissement de tout ce qui n'allait pas (highjack this, OTMoveIt, ccleaner, toolbar s&d). Désolé de te couper l'herbe sous le pied comme ça, mais, tu t'en doutes (c'est le cas pour tous les paumés/quiches comme moi), j'ai un besoin urgent de mon pc (je suis prof, et bon nombre de mes cours sont dessus !) En tout cas, je te remercie encore vivement de ton aide et de tes conseils, et merci pour ton dévouement ! Les gens comme toi sont rares. Bonne soirée Alex -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
J'ai réussi à virer Spyhunter (au démarrage, je me suis dépêché de cliquer sur Démarrer, dans la liste des programmes j'ai cherché Spyhunter, et j'ai fait Désinstaller => résultat l'ordi ne bugge plus au déparrage !!!!! Yeeeeeeeeeeeha !) J'ai donc téléchargé MBAM, et voici le rapport d'analyse: Malwarebytes' Anti-Malware 1.28 Version de la base de données: 1266 Windows 5.1.2600 Service Pack 2 13/10/2008 18:29:49 mbam-log-2008-10-13 (18-29-49).txt Type de recherche: Examen rapide Eléments examinés: 58974 Temps écoulé: 19 minute(s), 5 second(s) Processus mémoire infecté(s): 2 Module(s) mémoire infecté(s): 5 Clé(s) du Registre infectée(s): 34 Valeur(s) du Registre infectée(s): 12 Elément(s) de données du Registre infecté(s): 20 Dossier(s) infecté(s): 6 Fichier(s) infecté(s): 84 Processus mémoire infecté(s): C:\WINDOWS\system32\lphc7g0j0enhm.exe (Trojan.FakeAlert) -> Unloaded process successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\_A00F5EBBF.exe (Trojan.FakeAlert) -> Unloaded process successfully. Module(s) mémoire infecté(s): C:\WINDOWS\system32\efcYRlKD.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\rwlfsdmk.dll (Trojan.Zlob) -> Delete on reboot. C:\WINDOWS\system32\__c00CD100.dat (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\onfwbsak.dll (Trojan.FakeAlert) -> Delete on reboot. C:\WINDOWS\system32\blphc7g0j0enhm.scr (Trojan.FakeAlert) -> Delete on reboot. Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\CLSID\{36dc214c-02c4-4341-8a84-997f4772e1e5} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcyrlkd (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{87091271-33ea-4b86-98a1-237d055c104e} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\istx.installer.2 (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\qaccess.tchongabho (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a34fa88d-8437-4634-8a60-e913011ef2e5} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a34fa88d-8437-4634-8a60-e913011ef2e5} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2abe804b-4d3a-41bf-a172-304627874b45} (Adware.EGDAccess) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00cd100 (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{9c49f28f-9285-4659-9eb9-cee15da85009} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a87f2637-2d4b-46dc-8948-82a4451efd70} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{0fa15166-39da-4dab-9b1a-0dddbaca8bd5} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b917d91c-2b99-4ff8-acc2-f7972b7fdd16} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webvideo (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{d25118fc-cf56-4ed5-a669-a2e91ef1add9} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{95de3a2c-df48-4cdf-9bc8-36baee2288e2} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{aacce1f1-f0ad-429f-83d9-941bcfea335f} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{11dfb01a-0852-4955-9747-c59e21dbbda5} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11dfb01a-0852-4955-9747-c59e21dbbda5} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\peltodgx.batg (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\peltodgx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\AMeOpt (Adware.NetOptimizer) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{36dc214c-02c4-4341-8a84-997f4772e1e5} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\rwlfsdmk (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc7g0j0enhm (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f5ebbf.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0fa15166-39da-4dab-9b1a-0dddbaca8bd5} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\onfwbsak (Trojan.FakeAlert) -> Delete on reboot. HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully. Elément(s) de données du Registre infecté(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (55639-OEM-0011903-00100) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (HH:mm:ss) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Dossier(s) infecté(s): C:\Program Files\MyWay (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\History (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Settings (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache (Adware.MyWay) -> Quarantined and deleted successfully. Fichier(s) infecté(s): C:\WINDOWS\system32\efcYRlKD.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\rwlfsdmk.dll (Trojan.Zlob) -> Delete on reboot. C:\WINDOWS\system32\lphc7g0j0enhm.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\_A00F5EBBF.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Application Data\sp2\qaccess.dll (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\evqb.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\igiyvaey.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\dmbddv.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\nuidpjok.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\jkkHAqOh.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tuvVooop.dll (Trojan.Vundo) -> Delete on reboot. C:\Documents and Settings\Alexandre\Local Settings\Temporary Internet Files\Content.IE5\TL2Q8UXO\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temporary Internet Files\Content.IE5\5817H5C0\ihwd[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temporary Internet Files\Content.IE5\5817H5C0\cntr[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temporary Internet Files\Content.IE5\66GNNUZS\file[1].exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temporary Internet Files\Content.IE5\3WBQJN68\scan[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temporary Internet Files\Content.IE5\3WBQJN68\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\History\search (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Settings\prevcfg.htm (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\MYWAYPLUGINPROXY.CLASS (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER.BMP (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER2.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER3.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER4.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER5.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\2.bin\PARTNER6.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache\files.ini (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache\01E94F6D.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache\01E952A9.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache\01E95539.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache\01E96A0A (Adware.MyWay) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Application Data\Adobe\Player.exe (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\Downloaded Program Files\uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\__c00CD100.dat (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\peltodgx.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\onfwbsak.dll (Trojan.FakeAlert) -> Delete on reboot. C:\WINDOWS\fbxrqtwn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\dfmlxbpkvlo.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\blphc7g0j0enhm.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\phc7g0j0enhm.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\WINDOWS\tmlpcert2005 (Adware.EGDAccess) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Bureau\Protect Your Privacy.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Bureau\Malware Defender.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Bureau\System Error Fixer.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt15.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttF.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt9.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttA.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttE.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt5.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt6.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt7.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt8.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttC.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttB.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt10.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt14.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt15.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt17.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt18.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt19.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt1C.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt4.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt1.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt2.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt3.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt5.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt6.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.tt7.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttB.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\.ttC.tmp.vbs (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\pwrmgr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Alexandre\Local Settings\Temp\sft_ver1.1454.4.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully. ---------------------------------------------------------------------------------------------------------------- J'ai également un problème de redirection sous Google et Yahoo! Les pages de résultats s'affichent correctement, mais les liens me redirigent vers des adresses qui ne m'intéressent pas du tout. C'est d'ailleurs de cette manière que j'avais été redirigé vers une page où on me conseillait de télécharger Spyhunter. Que dois-je faire maintenant ? (la navigation présente de plus toujours des problèmes de lenteurs) Merci de ton aide !! -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Message inutile => supprimé -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Mon problème est que, à part les cd recovery que j'ai gravés quand j'ai eu l'ordi, je n'ai rien d'autre, et impossible de remettre la main sur la notice de l'ordi (elle est à mon avis partie à la poubelle lors de mon déménagement). Bref, comment faire pour tenter une réinstallation sans pertes si je n'ai pas le cd d'origine ? Je peux faire qq trucs, mais dès que Spyhunter se met en route, ça plante. Quand je dis "faire quelques trucs", généralement, j'essaie de désinstaller Spyhunter dès le démarrage: l'ordi me demande si je ne veux jeter que le raccourci à la corbeille, je réponds non, j'arrive sur Ajout/Suppression de programmes et là spyhunter se met en route (il semble programmé pour se mettre en route au démarrage de l'ordi) et ça plante. J'ai donc l'impression (peut être fausse) que c'est Spyhunter qui fait planter mon PC. En effet, avant que je ne le télécharge, l'ordi ne plantait pas. Il était lent, mais il ne plantait pas. -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Je récapitule: - en mode normal: j'arrive sur le bureau, antivir démarre (la petite fenêtre qui indique qu'il est présent), puis spyhunter aussi, et là l'ordi plante) - en mode sans échec: tiret blanc clignotant sur fond noir, et rien d'autre. - en mode sans échec avec prise en charge réseau: écran bleu avec "échec d'initialisation du pilote vidéo" Je ne rentre chez moi que demain, alors j'ai une petite question avant de commencer: il s'agit des cd que j'ai eu à graver juste après avoir acheté mon PC, ou c'est autre chose (et dans ce cas-là je le trouve où cet autre cd, parce que je ne l'ai jamais eu - merci Acer de fournir Windows directement installé...)? Est ce que ça va me supprimer les 2 virus, ou ça va juste permettre à mon ordi de redevenir docile ?? Bonne journée. -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Il a tourné 1h15-1h20. Mais il m'a bien dit que l'analyse était terminée. No errors detected. Press ESC to finish ou un truc dans ce genre. Je n'ai pas vu ce qui se passait, je l'ai laissé tourner pendant que j'allais faire des courses. En tout cas, aucun problème de trouvé. Et maintenant, qu'est ce qu'il faut que je fasse ? (je ne pourrai m'en occuper que jeudi maintenant). Merci de ton aide ! -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
j'ai laissé tourner jusqu'à ce qu'il me dise que c'était terminé. No errors detected. Il ne me laissait que ESC comme choix. -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Memset a terminé. Aucune erreur détectée. Bonne ou mauvaise nouvelle ? On fait quoi maintenant ?? -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
C'était bien le CD qui était mal gravé. Je l'ai lancé. je pars faire quelques courses, et je poste en revenant. Encore merci pour ton aide. -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
J'ai gravé le CD comme indiqué dans les tutos. La gravure s'est bien passée. Je suis allé dans le BIOS, il n'y avait rien à changer. J'ai mis le CD, et l'ordi ne boote pas dessus, MEMSET ne se met pas en route. J'ai essayé sur mes deux lecteurs (lecteur et graveur DVD). C'est grave docteur ???????? -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
AH oui, et merci pour ta réponse -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Juste une question avant que je me lance, je peux créer ce CD à partir de mon portable pour ensuite le lencer sur le PC fixe ? -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Personne pour m'aider ???? -
virus VIRTUMONDE et PRIVACYREMOVER
ltdpt a répondu à un(e) sujet de ltdpt dans Analyses et éradication malwares
Voilà ce que ça donne: - impossible de démarrer en mode normal: l'ordi plante au bout de 30 secondes après l'apparition du bureau, et je me retrouve avec un écran bleu qui dit: Stop c000021a {erreur système irrcupérable} Le processus système WINDOWS LOGON PROCESS s'est terminé de façon inattendue avec l'état 0xc0000005 (0x00000000 0x00000000) Le système a été arrêté - impossible de démarrer en mode sans échec: j'obtiens un tiret blanc qui clignote et rien d'autre - impossible de démarrer en mode sans échec avec prise en charge réseau: j'obtiens un écran bleu qui dit: échec d'initialisation du pilote vidéo. Je fais quoi maintenant ????? (précision: j'écris depuis mon portable, c'est mon pc fixe qui est infecté)