

likan03
Membres-
Compteur de contenus
2 -
Inscription
-
Dernière visite
likan03's Achievements

Junior Member (3/12)
0
Réputation sur la communauté
-
Infection ave.exe
likan03 a répondu à un(e) sujet de f.lopette dans Analyses et éradication malwares
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Version de la base de données: 4040 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 28/04/2010 14:53:09 mbam-log-2010-04-28 (14-53-09).txt Type d'examen: Examen complet (C:\|D:\|G:\|) Elément(s) analysé(s): 257891 Temps écoulé: 56 minute(s), 47 seconde(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 1 Clé(s) du Registre infectée(s): 3 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 2 Dossier(s) infecté(s): 5 Fichier(s) infecté(s): 70 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): C:\Windows\System32\cofiredm32.dll (Trojan.Tracur) -> Delete on reboot. Clé(s) du Registre infectée(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{14af72ff-dd6f-4ded-90d5-710e764efccc} (Trojan.BHO.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{14af72ff-dd6f-4ded-90d5-710e764efccc} (Trojan.BHO.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.fsharproj (Trojan.Tracur) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\cofiredm32.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\cofiredm32.dll -> Delete on reboot. Dossier(s) infecté(s): C:\ProgramData\1184404128 (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Roaming\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} (Worm.Prolaco.M) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Worm.Prolaco.M) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Worm.Prolaco.M) -> Quarantined and deleted successfully. Fichier(s) infecté(s): C:\ProgramData\dfscli32.dll (Trojan.BHO.H) -> Quarantined and deleted successfully. C:\Windows\System32\cofiredm32.dll (Trojan.Tracur) -> Delete on reboot. C:\ProgramData\api-ms-win-security-lsalookup-l1-1-032.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\Apphlpdm32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\appmgmts32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\avifile32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\bitsprx432.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\bootres32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\CertEnrollUI32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\cmpbk3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\comsnap32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\connect32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\CPFilters32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\cryptbase32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\cryptext32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\cryptui32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\ctl3d3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\d3d10_132.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\d3dim70032.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\dbnetlib32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\DDORes32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\defaultlocationcpl32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\deskadp32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\devenum32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\DeviceMetadataParsers32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\dhcpcmonitor32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\DiagCpl32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\dinput832.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\dmdlgs32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\dmstyle32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\ProgramData\dmutil32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\11E3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\1E00.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\24A1.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\5315.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\561E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\5B2B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\6CB7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\6ED0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\7271.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\730A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\76E7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\7CA2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\7F3A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\8362.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\881D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\8EEA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\9515.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\9B26.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\A3CE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\AB7B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\BFA7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\CAB2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\D38A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\DA19.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\DCC1.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\E28E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\E57E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\EE3B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\Temp\F37C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Roaming\SystemProc\lsass.exe (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Windows\System32\appidsvc32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Windows\System32\appmgmts32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Windows\System32\comctl3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully. G:\Divers\Vegas Pro 9\Keygen all product Sony\Keygen.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Worm.Prolaco.M) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Worm.Prolaco.M) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Worm.Prolaco.M) -> Quarantined and deleted successfully. C:\Users\Bidibulle\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully. C:\Users\Bidibulle\AppData\Local\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully. là je redémarre le pc et je continu pour le programme suivant : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:00:45, on 28/04/2010 Platform: Unknown Windows (WinNT 6.01.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16385) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchFilterHost.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU') O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\Windows\system32\cofiredm32.dll O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe -- End of file - 3839 bytes Donc voilà tout est fait, j'aimerais savoir si vous pouvez me décryptez tout çà et me dire si chui guéri merci ! -
Infection ave.exe
likan03 a répondu à un(e) sujet de f.lopette dans Analyses et éradication malwares
Bonjour, je détérre ce post j'en suis désolé mais j'ai le même problème, je vais suivre tout le tuto et je vous donne des nouvelles à très bientôt