Salut, je suis en train d'essayer de supprimer les virus présents sur le pc de ma copine mais j'ai quelques problèmes. J'ai lancé le scan malwarebytes, et après avoir vu les fichiers infectés j'ai soupçonné que windows allait bugger au démarrage vu que certains fichiers sont importants (svchost, win32, certains éléments du registre etc). Du coup je sais pas trop quoi faire, comment supprimer ces malwares sans faire bugger windows au démarrage vu qu'il manquera des éléments?
Voilà le rapport:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Version de la base de données: 8365
Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421
13/12/2011 14:56:10
mbam-log-2011-12-13 (14-56-10).txt
Type d'examen: Examen rapide
Elément(s) analysé(s): 199444
Temps écoulé: 5 minute(s), 25 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 14
Valeur(s) du Registre infectée(s): 12
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 3
Fichier(s) infecté(s): 28
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{1O83NV5O-O5TN-OKM6-53RO-H
UP3DO1Q4XNR} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1O83NV5O-O5TN-OKM6-53RO-HUP3DO1Q4XNR} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
es\ofhnhcel (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED
-7429D6C477A2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA
62-5422EB0D02FB} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220
-893DF03EC5DF} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Ext\Stats\{6FD31ED6-7C94-4BBC-8E95-F927F
4D3A949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AdVantage (Adware.Vomba) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Cerberus (Backdoor.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{42CY1512-JJ4H-4AC7-K68A-8
18UJI4JDIFL} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CY1512-JJ4H-4AC7-K68A-818UJI4JDIFL} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CY1512-JJ4H-4AC7-K68A-818UJI4JDIFL} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run\svchost (Trojan.Agent) -> Value: svchost -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\Explorer\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\lpkh3vvp.exe (Spyware.Password) -> Value: lpkh3vvp.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BB
E0-BCC03A819B3B} (Adware.Zango) -> Value: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BB
E0-BCC03A819B3B} (Adware.Zango) -> Value: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\Explorer\Run\Policies (Trojan.Agent) -> Value: Policies -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run\HKLM (Trojan.Agent) -> Value: HKLM -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\Policies (Trojan.Agent) -> Value: Policies -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\HKCU (Trojan.Agent) -> Value: HKCU -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Bad: (C:\Windows\System32.exe) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad:
(C:\Windows\system32\userinit.exe,C:\Windows\Syste
m32.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
c:\program files\shoppingreport (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files\shoppingreport\Bin (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files\shoppingreport\Bin\2.5.0 (Adware.ShopperReports) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
c:\Windows\System32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Win32\svchost.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Roaming\lpkh3vvp.exe
(Spyware.Password) -> Quarantined and deleted successfully.
c:\Windows\Temp\datb6bb.tmp.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Roaming\129931282.tm
p (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Roaming\41845630.tmp
(Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Roaming\41867610.tmp
(Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Roaming\91643957.tmp
(Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\0.0020651
72178232322.exe (Spyware.Password) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\0bf9eb01e
4516d1d1ce759176bc70540.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\133200938
_apoo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\133320529
_apoo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\14862184_
outfile-69957762.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\164192144
_f76cd0df84566190260fa588c567a823.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\19929034_
apoo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\11AD.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\144E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\ED1E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\F72E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\R66v.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\_97B7.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\propriétaire\downloads\INVedit.exe (Backdoor.Agent) -> Quarantined and deleted successfully.
c:\Users\propriétaire\downloads\keygen.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
c:\Windows\System32\drivers\str.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\svchost.e
xe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\propriétaire\AppData\Local\Temp\xxxyyyzzz
.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Windows\system\Steam.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Windows\System32\install\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.