CONNEXION
  • RetourJeux
    • Sorties
    • Hit Parade
    • Les + populaires
    • Les + attendus
    • Soluces
    • Tous les Jeux
    • Gaming
  • RetourActu Gaming
    • News
    • Astuces
    • Tests
    • Previews
    • Toute l'actu gaming
  • RetourBons plans
    • Bons plans
    • Bons plans Smartphone
    • Bons plans Hardware
    • Bons plans Image et Son
    • Bons plans Amazon
    • Bons plans Cdiscount
    • Bons plans Decathlon
    • Bons plans Fnac
    • Tous les Bons plans
  • RetourJVTech
    • Actus High-Tech
    • Intelligence Artificielle
    • Smartphones
    • Mobilité urbaine
    • Hardware
    • Image et son
    • Tutoriels
    • Tests produits High-Tech
    • Guides d'achat High-Tech
    • JVTech
  • RetourCulture
    • Actus Culture
    • Culture
  • RetourVidéos
    • A la une
    • Gaming Live
    • Vidéos Tests
    • Vidéos Previews
    • Gameplay
    • Trailers
    • Chroniques
    • Replay Web TV
    • Toutes les vidéos
  • RetourForums
    • Hardware PC
    • PS5
    • Switch 2
    • Xbox Series
    • Switch
    • Pokemon pocket
    • FC 25 Ultimate Team
    • League of Legends
    • Tous les Forums
  • PC
  • PS5
  • Xbox Series
  • Switch 2
  • PS4
  • One
  • Switch
  • iOS
  • Android
  • MMO
  • RPG
  • FPS
En ce moment Genshin Impact Valhalla Breath of the wild Animal Crossing GTA 5 Red dead 2
Liste des sujets

Suppression de malwares

Toutouyoutout
Toutouyoutout
Niveau 5
14 décembre 2011 à 23:25:01

Salut, je suis en train d'essayer de supprimer les virus présents sur le pc de ma copine mais j'ai quelques problèmes. J'ai lancé le scan malwarebytes, et après avoir vu les fichiers infectés j'ai soupçonné que windows allait bugger au démarrage vu que certains fichiers sont importants (svchost, win32, certains éléments du registre etc). Du coup je sais pas trop quoi faire, comment supprimer ces malwares sans faire bugger windows au démarrage vu qu'il manquera des éléments?

Voilà le rapport:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Version de la base de données: 8365

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

13/12/2011 14:56:10
mbam-log-2011-12-13 (14-56-10).txt

Type d'examen: Examen rapide
Elément(s) analysé(s): 199444
Temps écoulé: 5 minute(s), 25 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 14
Valeur(s) du Registre infectée(s): 12
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 3
Fichier(s) infecté(s): 28

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):

HKEY_CLASSES_ROOT\CLSID\{1O83NV5O-O5TN-OKM6-53RO-H
UP3DO1Q4XNR} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1O83NV5O-O5TN-OKM6-53RO-HUP3DO1Q4XNR} (Trojan.Agent.Gen) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
es\ofhnhcel (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED
-7429D6C477A2} (Adware.ShopperReports) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA
62-5422EB0D02FB} (Adware.ShopperReports) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220
-893DF03EC5DF} (Adware.ShopperReports) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Ext\Stats\{6FD31ED6-7C94-4BBC-8E95-F927F
4D3A949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AdVantage (Adware.Vomba) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Cerberus (Backdoor.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{42CY1512-JJ4H-4AC7-K68A-8
18UJI4JDIFL} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CY1512-JJ4H-4AC7-K68A-818UJI4JDIFL} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CY1512-JJ4H-4AC7-K68A-818UJI4JDIFL} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run\svchost (Trojan.Agent) -> Value: svchost -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\Explorer\Run\Cerberus (Trojan.Agent.Gen) -> Value: Cerberus -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\lpkh3vvp.exe (Spyware.Password) -> Value: lpkh3vvp.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BB
E0-BCC03A819B3B} (Adware.Zango) -> Value: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BB
E0-BCC03A819B3B} (Adware.Zango) -> Value: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Policies\Explorer\Run\Policies (Trojan.Agent) -> Value: Policies -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run\HKLM (Trojan.Agent) -> Value: HKLM -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Policies\Explorer\Run\Policies (Trojan.Agent) -> Value: Policies -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run\HKCU (Trojan.Agent) -> Value: HKCU -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Bad: (C:\Windows\System32.exe) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad:
(C:\Windows\system32\userinit.exe,C:\Windows\Syste
m32.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
c:\program files\shoppingreport (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files\shoppingreport\Bin (Adware.ShopperReports) -> Quarantined and deleted successfully.
c:\program files\shoppingreport\Bin\2.5.0 (Adware.ShopperReports) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
c:\Windows\System32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Win32\svchost.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Roaming\lpkh3vvp.exe
(Spyware.Password) -> Quarantined and deleted successfully.
c:\Windows\Temp\datb6bb.tmp.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Roaming\129931282.tm
p (Trojan.Dropper) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Roaming\41845630.tmp
(Trojan.Dropper) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Roaming\41867610.tmp
(Trojan.Dropper) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Roaming\91643957.tmp
(Trojan.Dropper) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\0.0020651
72178232322.exe (Spyware.Password) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\0bf9eb01e
4516d1d1ce759176bc70540.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\133200938
_apoo.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\133320529
_apoo.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\14862184_
outfile-69957762.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\164192144
_f76cd0df84566190260fa588c567a823.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\19929034_
apoo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\11AD.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\144E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\ED1E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\F72E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\R66v.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\_97B7.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\propriétaire\downloads\INVedit.exe (Backdoor.Agent) -> Quarantined and deleted successfully.
c:\Users\propriétaire\downloads\keygen.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
c:\Windows\System32\drivers\str.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\svchost.e
xe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\Users\propriétaire\AppData\Local\Temp\xxxyyyzzz
.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Windows\system\Steam.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Windows\System32\install\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.

macbrain
macbrain
Niveau 10
15 décembre 2011 à 00:10:38

créer un point de restau , supprime les avec malwares'byte anit malware ensuite tu verras! au pire tu rapelles ton point de restau et tu sera au même point de départ!

Toutouyoutout
Toutouyoutout
Niveau 5
15 décembre 2011 à 00:13:17

Je suis pas très malin j'aurais du préciser qu'en fait j'avais déjà tenté de le faire, et au redémarrage ça bug, c'est extrêmement long et maintenant je peux même plus vraiment démarrer en mode normal. Du coup de toute évidence y'a certains fichiers que je dois pas supprimer mais je sais pas lesquels, ni comment les désinfecter.

macbrain
macbrain
Niveau 10
15 décembre 2011 à 00:18:56

essayes spyboot , et asquared free avant de relancer un autre scann malware byte antimalwares

jerry_cane
jerry_cane
Niveau 10
15 décembre 2011 à 00:22:03

Voila ce qui arrive quand on s'amuse à utiliser des softs (yen très clair "keygen.exe") infectés :rire:

Sous forums
  • Aide à l'achat Mac
  • Création de sites web
  • Création de Jeux
  • Linux
  • Programmation
  • Internet
  • Steam Deck
  • Macintosh
  • Hardware
La vidéo du moment