Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

bonjour Pear, voici le rapport Kaspersky

 

 

-------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER REPORT

Monday, June 02, 2008 11:42:02 AM

Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)

Kaspersky Online Scanner version: 5.0.98.0

Kaspersky Anti-Virus database last update: 31/05/2008

Kaspersky Anti-Virus database records: 819344

-------------------------------------------------------------------------------

 

Scan Settings:

Scan using the following antivirus database: extended

Scan Archives: true

Scan Mail Bases: true

 

Scan Target - My Computer:

A:\

C:\

D:\

E:\

F:\

I:\

J:\

K:\

L:\

M:\

S:\

 

Scan Statistics:

Total number of scanned objects: 118266

Number of viruses found: 8

Number of infected objects: 106

Number of suspicious objects: 2

Duration of the scan process: 34:32:04

 

Infected Object Name / Virus Name / Last Action

C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver.zip/tsl2.exe Suspicious: Password-protected-EXE skipped

C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY.000\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY.000\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Toni\Application Data\m\data.oct Infected: Trojan-Downloader.Win32.Bagle.qz skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\cert8.db Object is locked skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\formhistory.dat Object is locked skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\history.dat Object is locked skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\key3.db Object is locked skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\parent.lock Object is locked skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\search.sqlite Object is locked skipped

C:\Documents and Settings\Toni\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\urlclassifier2.sqlite Object is locked skipped

C:\Documents and Settings\Toni\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Messenger\gloupy_99@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Messenger\gloupy_99@hotmail.com\SharingMetadata\pending.dat Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Messenger\gloupy_99@hotmail.com\SharingMetadata\Working\database_DE38_12AF_3812_86A5\dfsr.db Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Messenger\gloupy_99@hotmail.com\SharingMetadata\Working\database_DE38_12AF_3812_86A5\fsr.log Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Messenger\gloupy_99@hotmail.com\SharingMetadata\Working\database_DE38_12AF_3812_86A5\fsrtmp.log Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Messenger\gloupy_99@hotmail.com\SharingMetadata\Working\database_DE38_12AF_3812_86A5\tmp.edb Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Windows Live Contacts\GLOUPY_99@HOTMAIL.COM\real\members.stg Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Microsoft\Windows Live Contacts\GLOUPY_99@HOTMAIL.COM\shadow\members.stg Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\Cache\_CACHE_001_ Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\Cache\_CACHE_002_ Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\Cache\_CACHE_003_ Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Application Data\Mozilla\Firefox\Profiles\v1wapk84.default\Cache\_CACHE_MAP_ Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temp\Perflib_Perfdata_468.dat Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temp\~DF30A.tmp Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temp\~DF328.tmp Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temp\~DF7B37.tmp Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temp\~DF7B44.tmp Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_1[2].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_1[3].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_1[4].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_1[5].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_1[6].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_2[2].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_3[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_3[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\01W9Y385\b64_3[5].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64_2[2].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64_2[3].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64_2[4].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\1ZK8RUQC\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_1[2].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_1[3].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_1[4].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\2C4J40FO\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64_1[2].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7D494I5N\b64_3[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_1[2].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_1[3].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_1[4].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_1[5].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_2[2].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_2[3].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_2[4].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_3[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\7UCFBPC5\b64_3[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[5].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[6].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[7].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64[8].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_2[2].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_2[3].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_2[4].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\8X4N83OZ\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64_2[2].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64_2[3].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\R2P3B73I\b64_3[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64[5].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_1[2].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_1[3].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[1].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[2].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[3].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[4].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[5].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[6].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_2[7].jpg Infected: Email-Worm.Win32.Bagle.vr skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_3[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\Local Settings\Temporary Internet Files\Content.IE5\YLC3APQ5\b64_3[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Documents and Settings\Toni\ntuser.dat Object is locked skipped

C:\Documents and Settings\Toni\NTUSER.DAT.LOG Object is locked skipped

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080601-002815.log Object is locked skipped

C:\Program Files\LogMeIn\update\2-30-517.bak\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped

C:\Program Files\LogMeIn\update\2-30-537.bak\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped

C:\Program Files\LogMeIn\update\2-30-545.bak\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped

C:\Program Files\LogMeIn\update\2-30-547.bak\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c skipped

C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.d skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{D9C6A514-684A-4836-86FB-C1E8F70EB054}.crmlog Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\SoftwareDistribution\Download.old\dd9ab5193501484cf5e6884fa1d22f9e\backup\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\SoftwareDistribution\Download.old\fab149e21283fbaa0a0322fb64cc3aa3\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\SoftwareDistribution\Download.old\fd0264849c01086f3c6b505dc02dbd44\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped

C:\WINDOWS\system32\config\OSession.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\IdeChnDr.sys Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LMIinit.dll.000.bak Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.d skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

 

Scan process completed.

Posté(e) (modifié)

Bonjour,

 

Supprimez ces fichiers:

C:\Program Files\LogMeIn\update\*.bak

C:\WINDOWS\system32\LMIinit.dll.000.bak

 

Supprimez les fichiers Internet temporaires

 

le mode sans échec ne fonctionne pas

Bagle s'est réactivé.

C'est la raison des suppressions précédentes.

 

Relancez Elibagla en mode normal

Lorsque vous verrez Restaurada Clave: "SafeBoot\Minimal y Network",

Relancez le en mode sans échec.

Modifié par pear
Posté(e)

Alors, j'ai balancé les fichiers que vous m'avez indiqué, nettoyé les ficheiers internet temporaires.

 

J'ai relancé ELIBGAGLA, mais le programme s'arrête tout seul après 10-15 secondes de scan. (pas de messages d'erreurs, il disparait simplement de l'écran). J'ai déjà essayé 3x....

Posté(e)

Bonjour,

 

Imprimez ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

Télécharger Malwarebytes' Anti-Malware (MBAM)

Enregistrez le sur le bureau .

Fermer toutes les fenêtres et programmes.

Double-cliquer sur l'icône Download_mbam-setup.exe sur le bureau pour démarrer l'installation.

Suivez les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet).

N'apportez aucune modification aux réglages par défaut et, en fin d'installation,

vérifiez que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse.

cliquer sur OK pour fermer la boîte de dialogue.

La fenêtre principale de MBAM s'affiche :

Dans l'onglet analyse, vérifier que "Exécuter une analyse approfondie" est coché et cliquer sur le bouton Rechercher pour démarrer l'analyse.

L' analyse prendra un certain temps, soyez patient !

Un message s'affichera, en indiquant la fin .

Cliquer sur OK pour continuer.

Si des malwares ont été détectés, leur liste s'affiche.

En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse qui peut être retrouvé sous l'onglet Rapports/logs.

Fermer le bloc-note.

Fermer MBAM en cliquant sur Quitter.

Poster le rapport .

Posté(e)

Merci Pear,

 

juste pour info, après un 2ème reboot, elibagla s'est lancé correctement au démarrage. Il n'as plus trouvé de bagle. Mais j'ai un autre souci :P. encore un. Quand les icones apparaissent sur le bureau au démarrage de Windos, une fenetre explorer apparait "select file to crack". ! je ne sais pas ce que c'est. Si je ferme cette fenetre, 15 secondes plus tard windows plante (message de sécurité). Je ne sais pas ou aller chercher ce truc pour l'effacer.

 

Galère. Je vais néenmoins suivre vos instructions pour MBAM.

 

Merci de votre patience en tout cas. j'apprécie fortement...

Gloupy

Posté(e)

Bonsoir,

 

Content pour vous qu'Elibagla ait marché sans rien trouver.

 

démarrage de Windos, une fenetre explorer apparait "select file to crack"

 

On verra cela dans vos fichiers de démarrage : 04 dans hijackthis ou Ms config.

Posté(e)

Pear, voici l'analyse de Mbam

 

Malwarebytes' Anti-Malware 1.14

Version de la base de données: 815

 

20:34:08 02.06.2008

mbam-log-6-2-2008 (20-34-08).txt

 

Type de recherche: Examen complet (C:\|D:\|)

Eléments examinés: 141686

Temps écoulé: 27 minute(s), 3 second(s)

 

Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 0

Clé(s) du Registre infectée(s): 5

Valeur(s) du Registre infectée(s): 1

Elément(s) de données du Registre infecté(s): 0

Dossier(s) infecté(s): 0

Fichier(s) infecté(s): 7

 

Processus mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Module(s) mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Clé(s) du Registre infectée(s):

HKEY_CLASSES_ROOT\interface.interfaceobj (Adware.WebDir) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\interface.interfaceobj.1 (Adware.WebDir) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{58f07dd3-924d-4141-bc74-299f523a95f1} (Adware.WebDir) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{b1317c08-617a-435d-a24f-a930f4540696} (Adware.WebDir) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\AppID\pxwma.DLL (Adware.WebDir) -> Quarantined and deleted successfully.

 

Valeur(s) du Registre infectée(s):

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Delete on reboot.

 

Elément(s) de données du Registre infecté(s):

(Aucun élément nuisible détecté)

 

Dossier(s) infecté(s):

(Aucun élément nuisible détecté)

 

Fichier(s) infecté(s):

D:\System Volume Information\_restore{3E409C57-B2F8-42AC-9BCC-0ACCA5D26C96}\RP461\A0133755.EXE (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\srosa.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\mdelk.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\wintems.exe (Trojan.Agent) -> Delete on reboot.

C:\WINDOWS\system32\drivers\hldrrr.exe (Rootkit.Agent) -> Delete on reboot.

C:\Documents and Settings\Toni\Application Data\m\flec006.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\tmlpcert2005 (Adware.EGDAccess) -> Quarantined and deleted successfully.

Posté(e)

et bien je peu dire que c'est pratiquement rentré dans l'ordre. J ai pu réinstaller un antivirus. Mais j'attend votre feedback pour savoir si je dois faire autre chose.

 

Je crois avoir également viré cette fenêtre "file to crack".... Mais sans certitudes à 100%.

 

Gloupy

Posté(e)

Pear, voici un rapport de Elibagle lancé sous mode sans echec....

77 bagles trouvés....j'éspère que c'est pas heu grave....

 

Mon Jun 02 22:33:44 2008

EliBagle v11.44 ©2008 S.G.H. / Satinfo S.L. (Modificado el 29 de Mayo del 2008)

----------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\

C:\WINDOWS\system32\drivers\MDELK.EXE --> Eliminado Bagle.dldr

C:\WINDOWS\system32\drivers\downld\103304890.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\11270015.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\11334578.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\11668656.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\11735750.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\118097843.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\118175000.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\1213156.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\12426968.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\125109.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\126515.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\1274328.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\128421.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\1296625.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\132359.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\133734.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\137125.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\137765.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\141921.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\145421.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\146468.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14653640.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14659671.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14713703.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14736250.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14811875.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\148140.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14822265.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14824734.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14853031.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14886093.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14905375.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14914578.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\14970046.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\150343.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\153046.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\153500.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\157562.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\159296.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\160875.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\166937.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\16779078.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\168109.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\16851375.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\168703.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\170359.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\182984.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\187265.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\192609.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\206828.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\215031.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\219625.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\220796.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\2259062.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\2276906.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\227859.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\239078.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\244187.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\247140.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\266343.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\267109.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\29314593.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\29555421.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\295843.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\29650171.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\29675015.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\303531.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\376765.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\396671.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\44267406.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\44449734.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\44976484.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\45091203.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\73914609.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\73949281.EXE --> Eliminado Bagle

C:\WINDOWS\system32\drivers\downld\88518281.EXE --> Eliminado Bagle

 

Nº Total de Directorios: 9149

Nº Total de Ficheros: 90305

Nº de Ficheros Analizados: 23363

Nº de Ficheros Infectados: 77

Nº de Ficheros Limpiados: 77

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...