Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)



Voila comme tu la demander, je fait un nouveau poste pour plus de clarté :P. (Ceci dit c'est une bonne idée ^^)


Donc, j'ai exactement le meme probleme. J'ai eu ca ce soir, je n'ai absolument aucune idée de comment je l'ai DL ou chopper ca =/..


en resumer, j'ai eu plein de message d'alerte de mon antivirus : Avira Antivir. Un bonne 20taine...


Puis la plus aucune application ne peut se lancer, avec plein de message/alerte comme quoi le fichier .exe est infected. J'ai aussi plein de pub pour un anti virus, meme plusieurs differents.

Mais surtout Spyware Soft.


J'ai pu quand meme naviguer sur le net et rechercher des solution sur des forums. Je suis tomber ici entre autre.


J'ai fait deja qq manipulation tel que :


-redemarer en mode sans echec prise en charge du reseau, et supprimer des fichier dans des dossier au noms hasardeux et aléatoire --'. Comme indicé sur d'autre site.


-Spyware a quand meme pu se lancer.


-Ici j'ai pu lancer un programme proposé par un autre site : Malwarebytes' Anti-malware.

J'ai lancé un scan complet apres avoir mis a jour le programe. Ca a l'air de bien marché, il tourne deja depuis 1h15 et il a trouvé 35fichier infecté.


Merci :P.


EDIT : Je vient de voir que je suis dans une partie ou l'on demande des analyse, je vais avour que je ne m'y connais pas trop... Excuser moi si je suis un peu deboussolé ^^.


EDIT 2 : J'ai trouvé le programme avec lequel je scan ici : Malwarebytes' Anti-malware

Modifié par Monox


Et voila, MBAM a terminer et je poste le rapport ci dessous. Pas tres cool on dirait =/ ^^'

Malwarebytes' Anti-Malware 1.46


Version de la base de données: 4059


Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.11


2/05/2010 23:48:04

mbam-log-2010-05-02 (23-48-04).txt


Type d'examen: Examen complet (C:\|)

Elément(s) analysé(s): 287749

Temps écoulé: 1 heure(s), 37 minute(s), 14 seconde(s)


Processus mémoire infecté(s): 4

Module(s) mémoire infecté(s): 3

Clé(s) du Registre infectée(s): 14

Valeur(s) du Registre infectée(s): 7

Elément(s) de données du Registre infecté(s): 3

Dossier(s) infecté(s): 1

Fichier(s) infecté(s): 40


Processus mémoire infecté(s):

C:\WINDOWS\cidrive32.exe (Trojan.Dropper) -> Unloaded process successfully.

C:\Documents and Settings\JV\Local Settings\Temp\qhj0.exe (Backdoor.Bot) -> Unloaded process successfully.

C:\Documents and Settings\JV\Local Settings\Temp\qhj0.exe (Backdoor.Bot) -> Unloaded process successfully.

c:\lsass.exe (Trojan.Agent) -> Unloaded process successfully.


Module(s) mémoire infecté(s):

C:\WINDOWS\system32\msxsltsso.dll (Trojan.GootKit) -> Delete on reboot.

c:\WINDOWS\system32\sshnas21.dll (Trojan.Downloader) -> Delete on reboot.

C:\WINDOWS\system32\nmklo.dll (Worm.MarioFev) -> Delete on reboot.


Clé(s) du Registre infectée(s):

HKEY_CLASSES_ROOT\CLSID\{2ea62a30-2f5c-48a3-bb35-121159358426} (Trojan.GootKit) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ARManager (Rogue.ARManager) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sshnas (Trojan.Downloader) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\32 Vegas Casino (Adware.21Nova) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\32 Vegas Casino (Adware.21Nova) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\32 Vegas Casino (Adware.21Nova) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.


Valeur(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\appidyt_dlls (Spyware.Agent.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\gootkitsso (Trojan.GootKit) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\microsoft driver setup (Trojan.Dropper) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\s8g3 (Backdoor.Bot) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Rogue.ARManager) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\18451 (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.


Elément(s) de données du Registre infecté(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.


Dossier(s) infecté(s):

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811 (Trojan.Agent) -> Quarantined and deleted successfully.


Fichier(s) infecté(s):

C:\WINDOWS\system32\nmklo.dll (Spyware.Agent.H) -> Delete on reboot.

C:\WINDOWS\system32\msxsltsso.dll (Trojan.GootKit) -> Delete on reboot.

C:\WINDOWS\cidrive32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\JV\Local Settings\Temp\qhj0.exe (Backdoor.Bot) -> Delete on reboot.

C:\Documents and Settings\Administrateur\evmdfryt.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temp\448194,563388824.exe (Worm.Pinit) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temp\BN36.tmp (Trojan.Sasfis) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temp\husu.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temp\qhj0.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\2BEGAGUM\hypwhc[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\32BAIVNR\loaderadv600[1].exe (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\32BAIVNR\rvqxfn[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\32BAIVNR\xv4[1].txt (Backdoor.Bot) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\ZIR53WW9\msall[1].data (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\ZIR53WW9\pr3xy[1].data (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\JV\Local Settings\Temporary Internet Files\Content.IE5\58EJP2WB\msall[1].data (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\JV\Local Settings\Temporary Internet Files\Content.IE5\F6FYH0L8\hypwhc[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\JV\Local Settings\Temporary Internet Files\Content.IE5\XG9Q9KCA\hypwhc[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Worm.Autorun.B) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-1708537768-1292428093-725345543-500\Dc468.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-1708537768-1292428093-725345543-500\Dc469.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-1708537768-1292428093-725345543-500\Dc470.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-6207351980-6594324784-784017542-3982\mgrls32.exe (Worm.Autorun.B) -> Delete on reboot.

C:\System Volume Information\_restore{691F890E-8E93-4B94-A11E-1DF2ABED8EC9}\RP601\A0088154.exe (Trojan.FraudTool) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{691F890E-8E93-4B94-A11E-1DF2ABED8EC9}\RP601\A0088183.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{691F890E-8E93-4B94-A11E-1DF2ABED8EC9}\RP601\A0088188.exe (Rootkit.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\cooper.mine (Worm.Pinit) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\evmdfryt.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\ppufojrq.sys (Rootkit.Agent) -> Delete on reboot.

C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Favoris\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temp\nrktcvy.exe (Trojan.Agent) -> Delete on reboot.

C:\Program Files\Internet Explorer\js.mui (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\sshnas21.dll (Trojan.Downloader) -> Delete on reboot.

C:\Program Files\Internet Explorer\wmpscfgs.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\lsass.exe (Trojan.Agent) -> Delete on reboot.

C:\Documents and Settings\Administrateur\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.

C:\Program Files\Adobe\acrotray .exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\23rh46g.4e (Malware.Trace) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\bb52fkri.few (Malware.Trace) -> Quarantined and deleted successfully.

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...