Rootkit

Fermé
Deland - 29 juil. 2009 à 21:26
 Utilisateur anonyme - 30 juil. 2009 à 12:52
Bonjour,
Bonjour à vous tous, depuis quelques jours j'ai un rootkit sur mon poste je n'arrive pas a le supprimer pourtant j'ai fait une analyse colmplete avec Malwarebytes mais il est toujours present voici le rapport de l'analyse
A voir également:

7 réponses

Utilisateur anonyme
29 juil. 2009 à 21:29
salut quel est son nom ?
0
je ne connais pas son nom mais voici le rapport de l'analyse


Malwarebytes' Anti-Malware 1.39
Version de la base de données: 2421
Windows 5.1.2600 Service Pack 3

27/07/2009 00:43:01
mbam-log-2009-07-27 (00-43-01).txt

Type de recherche: Examen complet (C:\|E:\|)
Eléments examinés: 197282
Temps écoulé: 1 hour(s), 10 minute(s), 25 second(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 62

Processus mémoire infecté(s):
C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnlineGames) -> Delete on reboot.

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\csrcs (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Spyware.OnlineGames) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138619.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138610.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0137610.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136556.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136474.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136446.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0136563.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136491.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0135429.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0134412.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0134386.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0134369.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0134350.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136554.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136552.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136510.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP165\A0134276.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0134250.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0134233.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0136429.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP167\A0135436.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0134137.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132138.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132122.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132108.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132091.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132074.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132057.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132044.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0132021.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0129776.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP163\A0129763.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP163\A0129746.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP163\A0129732.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0129724.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128724.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128689.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128672.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128655.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128638.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128616.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128599.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP162\A0128582.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\8paf1d.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138617.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138616.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138615.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138608.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0138607.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0137608.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0137607.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP168\A0136558.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
c:\8paf1d.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0134331.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP166\A0134305.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP165\A0134294.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\autorun.inf (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\olhrwef.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnlineGames) -> Delete on reboot.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0134216.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
e:\system volume information\_restore{a0eff597-dee3-48a9-b1f8-0519754f2883}\RP164\A0134168.com (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
ort de l'analyse
0
je ne sais vraiment pas koi faire
0
Utilisateur anonyme
29 juil. 2009 à 21:49
bonsoir,
peut tu refaire un autre scan avec MBAM et poster son rapport stp
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
En fait je suis ds un cyber et je n'ai pas le pc pres demoi donc j'aimerai savoir s'il n'ya pas une methode pour eradiquer ce virus
0
excuse moi Asmal et Deland sont la meme personne
0
Utilisateur anonyme
30 juil. 2009 à 12:09
Bonjour,
il faut le rapport du pc directement, mais pour te dire aussi que le virus se trouve dans le point de restauration, il faut les virer aussi.
tu me tien au caourant dés que tu es devant ton pc

à+
0
Utilisateur anonyme
30 juil. 2009 à 12:52
laisse tomber MBAM pour le moment :

Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

! Déconnecte toi et ferme toutes tes applications en cours !

Double-clique sur " RSIT.exe " pour le lancer .

-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

* Devant l'option "List files/folders created ..." , tu choisis : 2 months

* clique ensuite sur " Continue " pour lancer l'analyse ...


-> laisse faire le scan et ne touche pas au PC ...


Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum


( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
0