Bonjour à vous,
1 - Sur le forum Kaspersky, un internaute américain m'a suggéré la procédure suivante (avec KIS 2010) :
- Please turn off Tracing. Located in Support Tools.
- You can delete them by disable Self defense (located in options), exit Kaspersky. Please turn on Self defense when done.
soit :
-
Interface principale\Utilitaires+\Suppression des traces d'activité et la suite.
- Mauvaise pioche : J'ai récolté des petites bêtes, le temps que
Self defense soit désactivé
(Interface principale\Configuration\Cliquer sur Paramètres\décocher Autodéfense)
2 - Ce que croient les victimes des"chronomètres à Ko" c'est que la suppression de ces fichiers (quelle que soit la procédure adoptée)
est définitive, alors que ces fichiers qui grossissent de façon continue
se recréent à chaque démarrage.
La seule procédure sans risque pour les supprimer est le mode sans echec.
Mais... voir (
2 ci-dessus).
Je n'ai pas encore trouvé la solution pour arrêter définitivement ce processus. Je cherche encore un peu, sinon je me résoudrai à interroger un ingénieur Kaspersky et je vous posterai évidemment sa réponse (s'il en a une...)
-------------------------------------------------------------------------------------------------------------
Ci-dessous mes Worm (en 2 passes de MBAM)
que Kaspersky n'a d'ailleurs pas décelés
PASSE 1 - Malwarebytes' Anti-Malware 1.40
Windows 5.1.2600 Service Pack 3 (Safe Mode)
20/08/2009 10:27:23
mbam-log-2009-08-20 (10-27-23).txt
Type de recherche: Examen complet (C:\|E:\|)
Eléments examinés: 145283
... / ...
Fichier(s) infecté(s):
14
C:\Documents and Settings\pc\Application Data\MSNInstaller\msnauins.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\ServicePackFiles\i386\digcore.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\ServicePackFiles\i386\msncli.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\ServicePackFiles\i386\msnsusii.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\ServicePackFiles\i386\netsetup.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\ServicePackFiles\i386\wextract.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\SoftwareDistribution\Download\513d22035389d6ef1cfe7e977f591f5380a0930d (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netsetup.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wextract.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\netsetup.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\wextract.exe (Worm.Autorun) -> Quarantined and deleted successfully.
E:\CD WINDOWS XP SP2 Home\VX2HOEM_FR (D)\I386\NETSETUP.EXE (Worm.Autorun) -> Quarantined and deleted successfully.
E:\CD WINDOWS XP SP2 Home\VX2HOEM_FR (D)\SUPPORT\TOOLS\FASTWIZ.EXE (Worm.Autorun) -> Quarantined and deleted successfully.
E:\CD WINDOWS XP SP2 Home\VX2HOEM_FR (D)\SUPPORT\TOOLS\MSRDPCLI.EXE (Worm.Autorun) -> Quarantined and deleted successfully.
-------------------------------------------------------------------------------------------------------------
PASSE 2 - Malwarebytes' Anti-Malware 1.40
Windows 5.1.2600 Service Pack 3 (Safe Mode)
20/08/2009 11:14:46
mbam-log-2009-08-20 (11-14-46).txt
Type de recherche: Examen complet (C:\|E:\|)
Eléments examinés: 145191
... / ...
Fichier(s) infecté(s):
13
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135688.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135689.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135690.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135691.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135692.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135693.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135694.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135695.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135696.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135697.exe
(Worm.Autorun) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135698.EXE
(Worm.Autorun) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135699.EXE
(Worm.Autorun) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{B8EA51D3-0393-40D0-8618-15B42320C830}\RP558\A0135700.EXE
(Worm.Autorun) -> Quarantined and deleted successfully.
-------------------------------------------------------------------------------------------------------------
Auriez-vous encore une suggestion ?
Merci d'avance
L'expérience est le meilleur des maîtres, car elle fait passer l'examen d'abord, et n'apprend la leçon qu'ensuite.