Hello,
Voila, je possède un Asus Eee PC que j'ai depuis bientôt un an et que j'utilise pour travailler. Et je ne fais que ça avec! Je n'ai jamais eu de problèmes.
Quand je l'ao allumé tout à l'heure, Avira Antivir n'a pas voulu se lancer. Et une petite bulle en bas à droite me dit que je suis infecté, et que quelqu'un tente de rentrer dans mon PC o_O. Après ça, un chargement se lance et des icônes de sites pornos apparaissent sur mon bureau...
J'ai lancé mon PC en mode sans échec et fais un scan avec antivir, qui m'a trouvé 22 fichiers infectés (qui sont soi-disant placés en quarantaine)!
Mais ils reviennent sans cesse.
Que faire? J'ai vraiment besoin d'aide.
PS: Je ne peux pas utiliser Antivir en mode normal.
PS2: J'ai Windows XP SP3.
PS3: Les virus en question sont:
- "TR/Ertfor.B.28"
- "TrojanASPX"
Merci à vous ![]()
Encore un truc : je suis un noob monumental en informatique, donc ne me parler pas chinois ![]()
Passe un coup d'antimalware :
http://www.clubic.com/telecharger-fiche215092-malwarebytes-anti-malware.html
En mode "normal" en espérant que ça fonctionne ![]()
Ok j'essaye ça ![]()
Quand je disais en mode normal ça voulait dire pas en mode sans echec quoi ![]()
Oui je sais, je ne suis pas aussi débile que ça
Enfin je pense ![]()
Pas bien d'aller sur des sites de pron ^^
![]()
http://noelshack4868397u7306.tk/
Je ne vais pas sur des sites pron'
, surtout pas avec mon petit PC de travail
Elle est vachement longue l'analyse de Malwarebytes ![]()
c'est très étrange alors , j'avais le même problème après avoir été sur des sites de pron , maintenant plus de problème .
Fais une restauration
![]()
http://noelshack4868397u7306.tk/
Je ne peux pas accéder à la restauration du système, ainsi qu'au gestionnaire des tâches
J'ai ce message "la restauration de systeme a été mise hors tension par la stratégie de groupe. Pour la restauration du systeme sous tention, veillez contacter l'administration de votre domaine".
:'(
hum télécharge hijackthis tu fais un scan et tu enregistre le log et tu le copie ici stp ![]()
A75
Ok je fais ça ![]()
Attention la dernière fois que j'ai demandé a A75 mon pc ne marchait plus ...
![]()
http://noelshack4868397u7306.tk/
L'analyse Malwarebytes vient de se terminer. Je dois "Supprmier la sélection"
Voici le rapport si vous le voulez:
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Version de la base de données: 3930
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
08/04/2010 21:16:17
mbam-log-2010-04-08 (21-16-17).txt
Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 193558
Temps écoulé: 31 minute(s), 21 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 4
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 15
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\p3coxe1u.dll (Trojan.Vundo.H) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Explorer\Browser Helper Objects\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a9ba40a1-74f1-52bd-f431-0
0b15a2c8953} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
es\_voidevximenwxv (Rootkit.TDSS) -> No action taken.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
es\_VOIDd.sys (Rootkit.TDSS) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\hsf87efjhdsf87f3jfsdi7fhsujfd (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Explorer\idstrf (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Explorer\winid (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> No action taken.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Dossier(s) infecté(s):
C:\WINDOWS\_VOIDevximenwxv (Rootkit.TDSS) -> No action taken.
Fichier(s) infecté(s):
C:\WINDOWS\system32\p3coxe1u.dll (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\116.exe (Trojan.Palevo.Gen.B8) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\406.exe (Trojan.Palevo.Gen.B4) -> No action taken.
C:\WINDOWS\_VOIDevximenwxv\_VOIDd.sys (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\system32\_VOIDwqltimrdly.dll (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\system32\_VOIDwtyhxexspd.dll (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\system32\_VOIDyepcfmlwme.dll (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\system32\_VOIDipyirjisbp.dat (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\_VOIDe123.tmp (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\Temp\_VOID1a35.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\csrss.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\services.exe (Password.Stealer) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Ryad\csrss.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Ryad\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> No action taken.
C'est long ![]()
Apparement ya un trojan dans ton pc , ca c'est chaud :s
![]()
http://noelshack4868397u7306.tk/
waouh tu es mal barré désolé pour toi mais tu t'es pris de bonne saletées, pour malwarebytes je dis rien car si tu supprime tout tu risque de supprimer certains fichier qui semble important, donc j'espère que tu as le cd de windows pour réparer, j'attends le log de hijackthis
Mon PC ne possède pas de lecteur CD... Et je n'ai pas le CD Windows
Le log arrive.
Pas bon tout ça, pas bon....
Supprimes les fichiers infectés avec malwarebyts, installe CCleaner pour qu'il te réparles les erreurs de registre... d'ailleurs les fichiers infectés touchent bien l'OS windows...
Je pense que tu n'avais pas d'antivirus auparavant ? si oui lequel ?
répare*