A voir également:
- Virus your protection meme probleme que Lolo
- Virus mcafee - Accueil - Piratage
- K9 web protection - Télécharger - Contrôle parental
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Protection cellule excel - Guide
16 réponses
bonjour
on sen fiche de son antivirus
il faut désinfecter
Pour de plus amples informations, fait ceci stp
Ouvre ce lien et télécharge ZHPDiag de Nicolas Coolman :
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Une fois le téléchargement achevé, dé zippe le fichier obtenu et place ZHPDiag.exe sur ton Bureau.
Double-clique sur l'icône pour lancer le programme. Sous Vista ou Seven clic droit « exécuter en tant que administrateur »
Clique sur la loupe pour lancer l'analyse.
Laisse l'outil travailler, il peut être assez long.
Ferme ZHPDiag en fin d'analyse.
Pour transmettre le rapport clique sur ce lien :
http://www.cijoint.fr/index.php
Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).
Sélectionne le fichier ZHPDiag.txt.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt
est ajouté dans la page.
Copie ce lien dans ta réponse.
on sen fiche de son antivirus
il faut désinfecter
Pour de plus amples informations, fait ceci stp
Ouvre ce lien et télécharge ZHPDiag de Nicolas Coolman :
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Une fois le téléchargement achevé, dé zippe le fichier obtenu et place ZHPDiag.exe sur ton Bureau.
Double-clique sur l'icône pour lancer le programme. Sous Vista ou Seven clic droit « exécuter en tant que administrateur »
Clique sur la loupe pour lancer l'analyse.
Laisse l'outil travailler, il peut être assez long.
Ferme ZHPDiag en fin d'analyse.
Pour transmettre le rapport clique sur ce lien :
http://www.cijoint.fr/index.php
Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).
Sélectionne le fichier ZHPDiag.txt.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt
est ajouté dans la page.
Copie ce lien dans ta réponse.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
bonjour
j'espere que tu es toujours la car je viens d'arreter l'analyse, et commnce ta procedure
merci
j'espere que tu es toujours la car je viens d'arreter l'analyse, et commnce ta procedure
merci
ne me contacte pas par MP
Téléchargez MalwareByte's Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
. Enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
. Une fois la mise à jour terminé
. Rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet (examen assez long)
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, clique sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. Rends toi dans l'onglet rapport/log
. Tu cliques dessus pour l'afficher, une fois affiché
. Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
. Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller
Si tu as besoin d'aide regarde ces tutoriels :
Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
Téléchargez MalwareByte's Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
. Enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
. Une fois la mise à jour terminé
. Rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet (examen assez long)
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, clique sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. Rends toi dans l'onglet rapport/log
. Tu cliques dessus pour l'afficher, une fois affiché
. Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
. Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller
Si tu as besoin d'aide regarde ces tutoriels :
Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
j'ai une fenetre avec ecrit que certain element n'ont pas pu être supprimer et le PC doit redemarer pour les supprimer
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Version de la base de données: 3970
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
09/04/2010 12:54:51
mbam-log-2010-04-09 (12-54-51).txt
Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 140357
Temps écoulé: 18 minute(s), 17 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 11
Valeur(s) du Registre infectée(s): 6
Elément(s) de données du Registre infecté(s): 4
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 63
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hf8wefhuaihf8ewfydiujhfdsfdf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\WINDOWS\_VOIDxtntovkora (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ititu523hq.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lb4ju06kw.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lopms5fp3q3xnf5.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\mdm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\smss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\sv8if7x.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\taskmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMP9BBE.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPBE6E.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5A1.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5FA.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPCE76.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ua8nyjt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\h5b9py99ck.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\asd7.tmp.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win16.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winamp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\auzdth.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\c07b5210.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\notepad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDc5c1.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDcf51.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ep32n9heca6ke5n.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\f0qi5t.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\742.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\user.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\vsoj0f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\p2ugykuc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\cmd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\urpprot.exe.VIR (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Uninstall.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urpext.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDimbcxotfub.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDpibeexurqp.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDxrbydlvmtt.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\bpebxwbe.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\gnjynng.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\lprad.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\syaixrk.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tyzvd.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\eaxllq.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\virus.mp3 (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Favoris\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Protection.lnk (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\fiosejgfse.dll (Rogue.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDyxvergewbc.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDa0d0.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2277.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID248a.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID290e.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2c3b.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\csrss.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
www.malwarebytes.org
Version de la base de données: 3970
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
09/04/2010 12:54:51
mbam-log-2010-04-09 (12-54-51).txt
Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 140357
Temps écoulé: 18 minute(s), 17 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 11
Valeur(s) du Registre infectée(s): 6
Elément(s) de données du Registre infecté(s): 4
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 63
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hf8wefhuaihf8ewfydiujhfdsfdf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\WINDOWS\_VOIDxtntovkora (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ititu523hq.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lb4ju06kw.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lopms5fp3q3xnf5.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\mdm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\smss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\sv8if7x.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\taskmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMP9BBE.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPBE6E.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5A1.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5FA.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPCE76.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ua8nyjt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\h5b9py99ck.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\asd7.tmp.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win16.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winamp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\auzdth.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\c07b5210.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\notepad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDc5c1.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDcf51.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ep32n9heca6ke5n.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\f0qi5t.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\742.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\user.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\vsoj0f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\p2ugykuc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\cmd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\urpprot.exe.VIR (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Uninstall.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urpext.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDimbcxotfub.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDpibeexurqp.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDxrbydlvmtt.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\bpebxwbe.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\gnjynng.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\lprad.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\syaixrk.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tyzvd.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\eaxllq.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\virus.mp3 (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Favoris\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Protection.lnk (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\fiosejgfse.dll (Rogue.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDyxvergewbc.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDa0d0.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2277.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID248a.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID290e.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2c3b.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\csrss.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Version de la base de données: 3970
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
09/04/2010 12:54:51
mbam-log-2010-04-09 (12-54-51).txt
Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 140357
Temps écoulé: 18 minute(s), 17 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 11
Valeur(s) du Registre infectée(s): 6
Elément(s) de données du Registre infecté(s): 4
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 63
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hf8wefhuaihf8ewfydiujhfdsfdf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\WINDOWS\_VOIDxtntovkora (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ititu523hq.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lb4ju06kw.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lopms5fp3q3xnf5.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\mdm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\smss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\sv8if7x.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\taskmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMP9BBE.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPBE6E.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5A1.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5FA.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPCE76.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ua8nyjt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\h5b9py99ck.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\asd7.tmp.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win16.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winamp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\auzdth.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\c07b5210.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\notepad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDc5c1.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDcf51.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ep32n9heca6ke5n.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\f0qi5t.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\742.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\user.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\vsoj0f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\p2ugykuc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\cmd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\urpprot.exe.VIR (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Uninstall.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urpext.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDimbcxotfub.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDpibeexurqp.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDxrbydlvmtt.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\bpebxwbe.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\gnjynng.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\lprad.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\syaixrk.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tyzvd.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\eaxllq.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\virus.mp3 (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Favoris\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Protection.lnk (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\fiosejgfse.dll (Rogue.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDyxvergewbc.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDa0d0.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2277.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID248a.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID290e.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2c3b.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\csrss.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
www.malwarebytes.org
Version de la base de données: 3970
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
09/04/2010 12:54:51
mbam-log-2010-04-09 (12-54-51).txt
Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 140357
Temps écoulé: 18 minute(s), 17 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 11
Valeur(s) du Registre infectée(s): 6
Elément(s) de données du Registre infecté(s): 4
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 63
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\_VOID (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a9ba40a1-74f1-52bd-f431-00b15a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hf8wefhuaihf8ewfydiujhfdsfdf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\WINDOWS\_VOIDxtntovkora (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection (Rogue.YourProtection) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ititu523hq.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lb4ju06kw.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lopms5fp3q3xnf5.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\mdm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\smss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\sv8if7x.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\taskmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMP9BBE.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPBE6E.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5A1.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPC5FA.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\TMPCE76.tmp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ua8nyjt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\h5b9py99ck.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\asd7.tmp.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win16.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\win32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winamp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\auzdth.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\avp32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\c07b5210.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\notepad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDc5c1.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDcf51.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\ep32n9heca6ke5n.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\f0qi5t.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\742.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\user.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\vsoj0f.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\p2ugykuc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\cmd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\urpprot.exe.VIR (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Uninstall.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urpext.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files\ZHPDiag\Quarantine\Your Protection.DIR\Your Protection\urphook.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDimbcxotfub.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDpibeexurqp.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDxrbydlvmtt.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\bpebxwbe.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\gnjynng.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\lprad.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\syaixrk.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tyzvd.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\eaxllq.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Your Protection\virus.mp3 (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Favoris\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Application Data\Microsoft\Internet Explorer\Quick Launch\Your Protection.lnk (Rogue.YourProtection) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\fiosejgfse.dll (Rogue.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_VOIDyxvergewbc.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\_VOIDa0d0.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2277.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID248a.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID290e.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\_VOID2c3b.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JPB Menuiserie\csrss.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\JPB Menuiserie\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
Lamer01
pourrais-tu simplement me confirmer que je peux le classer comme resolu stp ?
si c'est le cas, et quoiqu'il en soit merci infiniment de ton aide
je te dis pas à bientôt (ce qui signifirait que j'ai encore un soucis informatique)
pourrais-tu simplement me confirmer que je peux le classer comme resolu stp ?
si c'est le cas, et quoiqu'il en soit merci infiniment de ton aide
je te dis pas à bientôt (ce qui signifirait que j'ai encore un soucis informatique)
NON pas encore
j'ai une vie je suis pas toujours devant mon PC
Télécharge Ad-remover ( de C_XX ) sur ton bureau :
ici http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou ici https://www.androidworld.fr/
! Déconnecte toi, désactive ton anti-virus et ferme toutes applications en cours (Navigateur compris) !
* Double clique sur Ad-remover.exe qui est sur ton bureau pour lancer l'outil .
* Une fois l'outil ouvert, clique sur le bouton [Scanner] .
* Laisse travailler l'outil et ne touche à rien ...
--> Poste le rapport qui apparait à la fin dans ta prochaine pour analyse ...
( Le rapport est sauvegardé aussi sous C:\Ad-report-SCAN.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )
j'ai une vie je suis pas toujours devant mon PC
Télécharge Ad-remover ( de C_XX ) sur ton bureau :
ici http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou ici https://www.androidworld.fr/
! Déconnecte toi, désactive ton anti-virus et ferme toutes applications en cours (Navigateur compris) !
* Double clique sur Ad-remover.exe qui est sur ton bureau pour lancer l'outil .
* Une fois l'outil ouvert, clique sur le bouton [Scanner] .
* Laisse travailler l'outil et ne touche à rien ...
--> Poste le rapport qui apparait à la fin dans ta prochaine pour analyse ...
( Le rapport est sauvegardé aussi sous C:\Ad-report-SCAN.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )