Je viens de connecter un PC XP sp2 à l'internet via ADSL, sans avoir pris
le temps de mettre à jour l'antivirus...Je recommencerais plus, ça
m'apprendra...!
Après avoir passer une bonne demi-journée à rétablir la connexion, tout
nettoyer et mettre à jour, il subsiste le probleme suivant :
Zone alarm m'indique en permanence des tentatives de sorties sur le port
53 du programme mousecrm.exe. Un tcpdump indique qu'il s'agit sans doute
d'un scan d'adresses IP...Le pare-feu les bloque, mais j'ai encore qques
soucis dans la stabilité de la connexions ADSL (perte de 5 à 30% des
paquets sur un ping...)
Antivir a retiré les trojan pakes.14 et lowzone. Depuis, j'ai passé a-
square, ad-aware, spybot, et antivir, tous "up-to-date", en mode sans
échec et en mode normal, sans résultat.
Antivir retrouve aléatoirement pakes.14 et le vire. Le scan d'après est
nif, mais deux heures plus tard, il est encore là, alors que l'antivirus
a toujours été actif...
De plus, régulièrement, j'ai des tentatives d'inscription d'une clé
nommée OE_WMPWMFSDF_install_X (ou X varie entre 0 et 30), que je bloque
via spybot...
Accessoirement, le PC est à jour question maj windows update.
Si quelqu'un a une idée, un outil magique, je suis preneur.
Cette action est irreversible, confirmez la suppression du commentaire ?
Signaler le commentaire
Veuillez sélectionner un problème
Nudité
Violence
Harcèlement
Fraude
Vente illégale
Discours haineux
Terrorisme
Autre
Chris Evans
Okay, I babelfished you and I think I understand now. You can remove the trojan by booting to safe mode and deleting the mousecrm.exe and the x.tmp (where x equals an int).
You will have to unhide the mousecrm.exe file to delete it.
Also, it'll leave a reference to the mousecrm.exe in your registry that you may want to delete.
Okay, I babelfished you and I think I understand now. You can remove
the trojan by booting to safe mode and deleting the mousecrm.exe and
the x.tmp (where x equals an int).
You will have to unhide the mousecrm.exe file to delete it.
Also, it'll leave a reference to the mousecrm.exe in your registry that
you may want to delete.
Okay, I babelfished you and I think I understand now. You can remove the trojan by booting to safe mode and deleting the mousecrm.exe and the x.tmp (where x equals an int).
You will have to unhide the mousecrm.exe file to delete it.
Also, it'll leave a reference to the mousecrm.exe in your registry that you may want to delete.
Christophe ALLARD
"Chris Evans" écrivait news::
Okay, I babelfished you and I think I understand now. You can remove the trojan by booting to safe mode and deleting the mousecrm.exe and the x.tmp (where x equals an int).
You will have to unhide the mousecrm.exe file to delete it.
Also, it'll leave a reference to the mousecrm.exe in your registry that you may want to delete.
(my english's not so good as i want...sorry)
I make that at first, but i was in trouble about the mousecrm.exe : i don't find anything on the net about this file and i'm suppose it was a windows system file...(usually, i use linux) So i undelete all the file... What's the name of this trojan ? pakes ?
Okay, I babelfished you and I think I understand now. You can remove
the trojan by booting to safe mode and deleting the mousecrm.exe and
the x.tmp (where x equals an int).
You will have to unhide the mousecrm.exe file to delete it.
Also, it'll leave a reference to the mousecrm.exe in your registry that
you may want to delete.
(my english's not so good as i want...sorry)
I make that at first, but i was in trouble about the mousecrm.exe : i don't
find anything on the net about this file and i'm suppose it was a windows
system file...(usually, i use linux) So i undelete all the file...
What's the name of this trojan ? pakes ?
Okay, I babelfished you and I think I understand now. You can remove the trojan by booting to safe mode and deleting the mousecrm.exe and the x.tmp (where x equals an int).
You will have to unhide the mousecrm.exe file to delete it.
Also, it'll leave a reference to the mousecrm.exe in your registry that you may want to delete.
(my english's not so good as i want...sorry)
I make that at first, but i was in trouble about the mousecrm.exe : i don't find anything on the net about this file and i'm suppose it was a windows system file...(usually, i use linux) So i undelete all the file... What's the name of this trojan ? pakes ?