Win32.TrojanDownloader.Agent - Page 2

Précédent
  • 1
  • 2
podrob Messages postés 15 Statut Membre
 
Mmh en attendant je me demandais, je devrais pas désactiver la restoration système ? Je vois que MB trouve des merdes dans le dossier c:\system volume information\_restore_blahblah

C'est pas lié ?
0
Utilisateur anonyme
 
Re,

Si t'as resto et infecter mais sa on le feras en fin.
0
podrob Messages postés 15 Statut Membre
 
Bon voilà un log Malware Byte. C'est le 3ème et il trouve de plus en plus d'éléments infectés !

Le log après vidange de la quarantaine :

Malwarebytes' Anti-Malware 1.33
Version de la base de données: 1654
Windows 5.1.2600 Service Pack 2

16/01/2009 20:52:33
mbam-log-2009-01-16 (20-52-33).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 103663
Temps écoulé: 19 minute(s), 15 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 29
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 11
Fichier(s) infecté(s): 40

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\csrss.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Not selected for removal.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\b54321.ieencryptapp (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{09eb15fa-17d8-4d60-8598-3f549a848df2} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09eb15fa-17d8-4d60-8598-3f549a848df2} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09eb15fa-17d8-4d60-8598-3f549a848df2} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\newadpopup.toolbardetector (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\newadpopup.toolbardetector.1 (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0ad3ab16-6d0e-4f04-8660-fb1f36bc2dc0} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2f685b36-c53a-4653-9231-1dae5736de45} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{50c4cdd9-22d7-49ff-ac6d-7d4d528a3ab2} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f9ba1aa9-cad4-4c14-bde6-922dff5f6f38} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7dbc6adb-5788-4fb9-aec3-b40a58ac11df} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cde9eb54-a08e-4570-b748-13f5ddb5781c} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{34a12a06-48c0-420d-8f11-73552ee9631a} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{11f09afd-75ad-4e51-ab43-e09e9351ce16} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{de2267bd-b163-407f-9e8d-6adec771e7ab} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11f09afd-75ad-4e51-ab43-e09e9351ce16} (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11f09afd-75ad-4e51-ab43-e09e9351ce16} (Adware.CPush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{68f25c63-e798-4255-89ce-243aa3757638} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{68f25c63-e798-4255-89ce-243aa3757638} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7dbc6adb-5788-4fb9-aec3-b40a58ac11df} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msiffei (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\apcdli (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\Effects\YiqilaiLyrics (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YiqilaiLyrics (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Yiqilai (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\newpush (Adware.CPush) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\cpush (Adware.CPush) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MicroPlugins (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ContentMatch (Adware.CPush) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Alcmtr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HBService32 (Trojan.Agent) -> Delete on reboot.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\Common Files\PushWare (Adware.CPush) -> Delete on reboot.
C:\Program Files\Yiqilai (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\foobar (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\html (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\iTunes (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\lib (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\realplayer (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\tools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\winamp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\wmp (Trojan.Agent) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\Internet Explorer\PLUGINS\b54321.bho (Spyware.OnlineGames) -> Delete on reboot.
C:\Documents and Settings\Rob\Local Settings\Temp\11529.dll (Trojan.Starter) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rob\Local Settings\Temp\84a1.dll (Trojan.Starter) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rob\Local Settings\Temp\fd0d.dll (Trojan.Starter) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rob\Local Settings\Temp\suchots.exe (Trojan.Ducky) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rob\Temporary Internet Files\Content.IE5\1N3C0V26\newads26[1].exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rob\Temporary Internet Files\Content.IE5\1N3C0V26\newads28[1].exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rob\Temporary Internet Files\Content.IE5\3DJLO6MW\newads21[1].exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\anymie360.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\PushWare\cpush.dll (Adware.CPush) -> Delete on reboot.
C:\Program Files\Common Files\PushWare\Uninst.exe (Adware.CPush) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\foobar\foo_ui_columns.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\foobar\foo_ui_yqllyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\iTunes\iTunesYQLyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\lib\YQL_Lyrics_Common.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\realplayer\RealYQLyrics.rpv (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\foo_ui_columns.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\foo_ui_yqllyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\gen_yqllyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\iTunesYQLyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\RealYQLyrics.rpv (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\vis_yqllyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\Temp\Ò»ÆðÀ´ÒôÀÖÖúÊÖ°ïÖú.url (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\tools\GetMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\tools\music.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\tools\YiqilaiLyrics.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\winamp\gen_yqllyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\winamp\vis_yqllyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Yiqilai\wmp\YiqilaiLyrics.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\System.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\csrss.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Not selected for removal.
C:\WINDOWS\system32\YQL_Lyrics_Common.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\HBWULIN2.dll (Spyware.OnlineGames) -> Delete on reboot.
C:\WINDOWS\system32\HBCHIBI.dll (Spyware.OnlineGames) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2263.dll (Adware.CPush) -> Delete on reboot.
C:\Documents and Settings\Rob\Favorites\Ò»ÆðÀ´ÒôÀÖÉçÇø.url (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\cpush.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\YiqilaiLyrics_2001.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Je reboot pour un scan RSIT...
0
Utilisateur anonyme
 
Re,

-Tu utilises une version pirate de WINDOWS;

J'utilise une version piratée de Windows

Pourquoi CCM n'aide pas à pirater des logiciels

Charte d'utilisation de CommentCaMarche.net - Aspects légaux

le bonus

Le super bonus
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
podrob Messages postés 15 Statut Membre
 
Oooh désolé de t'avoir fait perdre ton temps alors. Sincèrement.

Je ne savais pas que ce genre de principes étaient d'actualité ici, j'ai cru que ce forum était une endroit ou la majorité des utilisateurs "casual" pouvaient exprimer leurs problèmes. Car on sait tous qu'il y a plus de particuliers "pirates", que de particuliers propriétaire d'une licence bien sûr...

Soit, loin de moi l'idée de lancer un débat stérile sur le prix des licences Windows, ou pire sur leur rapport qualité/prix !!! Non je veux juste m'excuser de t'avoir fait perdre ton temps.

Je vais encore passer quelques scans mais le problème semble récurent et je n'ai pas les compétences requises pour m'en débarasser. Un petit format C: fera l'affaire, et c'est reparti pour deux ans... for free ! ;)

ps : Si mes jeux tournaient sous Linux, je me transformerais en Pingouin bien volontier. Malheureusement, j'aime le jeu vidéo et dans cette mesure, je n'ai pas bcp de choix. Pourquoi devrai-je payer pour une olbligation dictée par les lois de la demande et du marché ?

Merci encore pour ton aide ;)
0
podrob Messages postés 15 Statut Membre
 
ps: Ton super bonus est très amusant et fera certainement peur à...mmmh...personne à l'heure actuelle ? :D

psII : Enfin si c'était de l'humour j'ai bien aimé.
0
Précédent
  • 1
  • 2