Hello
Depuis peu de temps j'ai un message d'erreur qui apparait pres de l'horloge de l'ordi
Qui me dit que je suis infecter ect...
Et j'arrive pas a m'en debarasser >.<
attends wiwi
mdr
j'ai screen ce que sa me donné
http://img397.imageshack.us/img397/7959/sanstitre3wj9.png
http://img397.imageshack.us/img397/2259/sanstitre2vl4.jpg
Commence par télécharger ceci.
http://perso.orange.fr/ill.mafioso/Navifix/Navilog1.exe
Ensuite tu ouvres l'exe et tu fais l'option 1.
Voila c'est faity je dois te c/c sa ?
Tu pourrais écrire mieux s'il te plait.
A par un y en trop je vois pas ce qui est imcomprehensible
Peu etre c/c = Copier coller x)
Oui tu colles le rapport.
pour + d'infos : http://www.gmer.net
Aucun Fichier trouvé
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
3)Recherche Certificats :
Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
C:\WINDOWS\system32\ihhkj.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ihhkj.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ihhkj.bak2 trouvé ! infection Vundo possible non traitée par cet outil !
Bon je vois que tu as une infection Vundo.
Attends Wiwi77.
Okay merci a toi c'est grave cette infection ? : o
Oui quand même, je me demande comment tu l'as choppé.
Bah j'ai recu un message qui ma dit qu'il me manqué un composant d'active X la premiere fois j'ai fermer la fenetre
Pi il est revenu et ma lancer le programme (j'ai surment du cliqué au moment ou il est revenu >.<)
Les antivirus ont rien detecté :'(
Install et fait un scan avec MalwareByte's Anti-Malware.
Lien: http://www.malwarebytes.org/mbam/program/mbam-setup.exe .
Tuto: http://www.malekal.com/tutorial_MalwareBytes_AntiMalware.php
Normalement après avoir fait sa et avoir redemmaré sa devrais être réglé ![]()
Salut,
Tony, je doute que MAM trouve tous les fichiers Vundo.
Bah voila le scan viens de finir (c'etait long ><)
et tout a disparu apparement y'a plus rien merci a vous <3
Poste le rapport.
Processus mémoire infecté(s): 4
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 22
Valeur(s) du Registre infectée(s): 8
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
C:\Program Files\Web Technologies\iebtm.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebtmm.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\wcm.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\wcs.exe (Trojan.Zlob) -> No action taken.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\blbpeoy.dll (Trojan.Zlob) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{ecc974ae-6ede-44a2-90da-9
3b996d8eaf8} (Trojan.Zlob) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{85bdd81d-31fd-4a6b-a73c-3
955b128d2ec} (Trojan.Zlob) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{b8301af7-d00e-4ea4-87c1-5
ff4644fbba1} (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Explorer\Browser Helper Objects\{b8301af7-d00e-4ea4-87c1-5ff4644fbba1} (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{9034a523-d068-4be8-a284-9df27
8be776e} (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c6
6eff1d302} (Search.Hijack) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5adf3862-9e2e-4ad3-86f7-4
510e6550cd0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32 (Dialer) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\aldd (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Web Technologies (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\IEBrowse Tool (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\IExplorer Bar (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\Warning Center (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PSRV (Trojan.Agent) -> No action taken.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DomainServic
e (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CAC (Malware.Trace) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Explorer\SharedTaskScheduler\{ecc974ae-
6ede-44a2-90da-93b996d8eaf8} (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{85bdd81d-31fd-4a6b-a7
3c-3955b128d2ec} (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\start (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\some (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{07aa283a-43d7-4cbe-a0
64-32a21112d94d} (Adware.Zango) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> No action taken.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Web Technologies (Trojan.Zlob) -> No action taken.
Fichier(s) infecté(s):
C:\WINDOWS\system32\blbpeoy.dll (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebr.dll (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebt.dll (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebtm.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebtmm.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebtu.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\iebu.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\myd.ico (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\mym.ico (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\myp.ico (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\myv.ico (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\ot.ico (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\ts.ico (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\wcm.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\wcs.exe (Trojan.Zlob) -> No action taken.
C:\Program Files\Web Technologies\wcu.exe (Trojan.Zlob) -> No action taken.
C:\Documents and Settings\All Users\Menu Démarrer\Antivirus Scan.url (Trojan.Zlob) -> No action taken.
C:\Documents and Settings\All Users\Menu Démarrer\Online Spyware Test.url (Trojan.Zlob) -> No action taken.
C:\WINDOWS\retadpu1000272.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\sousou\Favoris\Antivirus Scan.url (Rogue.Link) -> No action taken.
J'ai aussi sa
Processus mémoire infecté(s): 4
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 22
Valeur(s) du Registre infectée(s): 8
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
C:\Program Files\Web Technologies\iebtm.exe (Trojan.Zlob) -> Unloaded process successfully.
C:\Program Files\Web Technologies\iebtmm.exe (Trojan.Zlob) -> Unloaded process successfully.
C:\Program Files\Web Technologies\wcm.exe (Trojan.Zlob) -> Unloaded process successfully.
C:\Program Files\Web Technologies\wcs.exe (Trojan.Zlob) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\blbpeoy.dll (Trojan.Zlob) -> Unloaded module successfully.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{ecc974ae-6ede-44a2-90da-9
3b996d8eaf8} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{85bdd81d-31fd-4a6b-a73c-3
955b128d2ec} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b8301af7-d00e-4ea4-87c1-5
ff4644fbba1} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Explorer\Browser Helper Objects\{b8301af7-d00e-4ea4-87c1-5ff4644fbba1} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Extensions\{9034a523-d068-4be8-a284-9df27
8be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c6
6eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5adf3862-9e2e-4ad3-86f7-4
510e6550cd0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32 (Dialer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Web Technologies (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\IEBrowse Tool (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\IExplorer Bar (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\Warning Center (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PSRV (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DomainServic
e (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CAC (Malware.Trace) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Explorer\SharedTaskScheduler\{ecc974ae-
6ede-44a2-90da-93b996d8eaf8} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{85bdd81d-31fd-4a6b-a7
3c-3955b128d2ec} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\start (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\some (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{07aa283a-43d7-4cbe-a0
64-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Web Technologies (Trojan.Zlob) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS\system32\blbpeoy.dll (Trojan.Zlob) -> Delete on reboot.
C:\Program Files\Web Technologies\iebr.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\iebt.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\iebtm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\iebtmm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\iebtu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\iebu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\ot.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\ts.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\wcm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\wcs.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Web Technologies\wcu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\WINDOWS\retadpu1000272.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\sousou\Favoris\Antivirus Scan.url (Rogue.Link) -> Quarantined and deleted successfully.
Supprime la sélection.
MAM ne suffira pas même si tu dis que le PC est nickel.