Comment savoir si mon pc est infécter

Bonsoir,

voila je pense que mon pc est peut-être infecter car mon firewell (zone alarme) me demande si j'autorise ou

refuse SUPbackground.exe d'acceder à internet. Mais je ne c'est pas c'est quoi donc souvent j'autorise.

Donc je viens vers vous pour savoir : Comment savoir si mon pc est infecter

(petit Help me)

27 réponses

Résumé de la discussion

Un utilisateur s'inquiète d'une alerte du pare-feu demandant d'autoriser SUPbackground.exe à accéder à Internet et cherche comment vérifier une éventuelle infection. Des réponses recommandent des analyses approfondies avec Malwarebytes, mise à jour des définitions et vérification des résultats, puis suppression des éléments détectés et génération d'un rapport. D'autres conseils évoquent HijackThis, la conservation du pare-feu actif, l'utilisation de navigateurs plus sûrs comme Firefox, et l'obligation de partager les rapports pour évaluer l'état. En dernier, l'analyse complète a finalement révélé aucun fichier ou processus infecté, même si l'agent insiste sur la poursuite des scans jusqu'à confirmation et surveillance.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Je corrigerai cette petite lacune ;-)

    ▶ Télécharge malwarebyte's anti-malware

    ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

    ▶ Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

    ▶ Lance une analyse complète en cliquant sur "Exécuter un examen complet"

    ▶ Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

    ▶ L'analyse peut durer un bon moment.....

    ▶ Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

    ▶ Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

    ▶ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

    * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée
    1
    1. Contributeur sécurité
      Chrome n'est pas la meilleur façon de naviguer en sécurité... Je te conseillerais plutôt de surfer avec Firefox qui est rapide et sécurisé.
      1
      1. Contributeur sécurité
        Bonsoir,

        ▶ Télécharge hijackthis

        ▶ Tout est expliqué sur mon site web pour l'installer et l'utiliser correctement.

        ▶ Poste le rapport obtenu dans le bloc note dans ta prochaine réponse.

        Comment copier/coller le rapport :

        ▶ Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

        ▶ ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
        0
        1. re

          ya pas le rapport sur le bloc note

          je suis sur hostspot neuf c peut etre pour sa
          0
          1. Contributeur sécurité
            As-tu cliqué sur "do a system scan and save a logfile" ??
            0
            1. ouai je lai fais il commence a le faire puis il met sa : (je lai recopier)

              For some reason your system denied write access to the Hosts file. If any hijacked domains are in this life, HijackThis may NOT be able to fix this.

              If that happens, you need to edit the file yourself. To do this, click Start, Run and type :

              notepadC:\Windows\System32\drivers\etc\hots

              and press Enter. Find the line(s) HijackThis reports and delete them.
              Save the file as "hosts." (with quotes), and reboot.

              For vista : simply, exit HijackThis, right click on the HijackThis icon, choose "Run as administrator".
              0
              1. et ya rien sur le bloc note il est vide
                0
                1. Contributeur sécurité
                  Tu es sous vista ??
                  0
                  1. Contributeur sécurité
                    Fais un clic droit sur hijackthis et sélectionne "Exécuter en tant qu'administrateur" ;-)
                    0
                    1. clic droit sur hijackthis ( l icone)

                      et choisir executer en tant qu administrateur ..

                      0
                      1. Contributeur sécurité
                        lol...

                        Salut chiqui ;-)
                        0
                        1. ba voila lool fallait le préciser sur ton site ^^

                          don voila le rapport :

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 19:52:29, on 12/03/2009
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18372)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
                          C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
                          C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
                          C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Windows\System32\rundll32.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\Athan\Athan.exe
                          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Users\SAMSUNG\AppData\Local\Google\Update\GoogleUpdate.exe
                          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                          C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Windows\system32\NOTEPAD.EXE
                          C:\Program Files\Trend Micro\HijackThis\HJT.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
                          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [Google Update] "C:\Users\SAMSUNG\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Global Startup: BTTray.lnk = ?
                          O8 - Extra context menu item: Consulter les dictionnaires (SYSTRAN) - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/lookup.js
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O8 - Extra context menu item: Traduire (SYSTRAN) - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/translate.js
                          O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - (no file)
                          O9 - Extra 'Tools' menuitem: iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - (no file)
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                          O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                          O13 - Gopher Prefix:
                          O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                          O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
                          O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - D:\maconfservice.exe (file missing)
                          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
                          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                          O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                          O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
                          0
                          1. lol

                            t as été plus rapide ;)

                            des kiss

                            je vais te mp ..

                            0
                            1. re,

                              j ai juste une question : ton pc rame ?

                              C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chr­ome.exe
                              C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chr­ome.exe
                              C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chr­ome.exe
                              C:\Users\SAMSUNG\AppData\Local\Google\Chrome\Application\chr­ome.exe
                              0
                              1. oui c vrai ki rame, je le remarque quand je surf sur le net.

                                google chrome n'arrive plus a charger la page (ex : skyrock )

                                et je doi donc redémarer mon pc

                                tu connais la solution
                                0
                                1. ok ok
                                  il ne fau pas desactiver mon pare feu mon anti virus
                                  0
                                  1. Contributeur sécurité
                                    Non pas besoin ;-)
                                    0
                                    1. me revoila ^^

                                      ba aucun élément infecter ! (pas compris pk il rame alors mon pc)

                                      voici le rapport d'analyse :

                                      Malwarebytes' Anti-Malware 1.34
                                      Version de la base de données: 1841
                                      Windows 6.0.6001 Service Pack 1

                                      12/03/2009 21:30:22
                                      mbam-log-2009-03-12 (21-30-22).txt

                                      Type de recherche: Examen complet (C:\|D:\|)
                                      Eléments examinés: 184049
                                      Temps écoulé: 1 hour(s), 22 minute(s), 59 second(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 0
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 0

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      (Aucun élément nuisible détecté)
                                      0
                                      • 1
                                      • 2