Virus pub?? - Page 2

  1. Oui malheureusement :S C'est un petit peu génant car c'est mon outil de travail donc attendre 5 minutes des fois sa énerve :S
    0
    1. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

      ? Télécharge List_Kill'em et enregistre le sur ton bureau
      http://sd-1.archive-host.com/...
      double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

      Une fois terminée , clic sur "terminer" et le programme se lancera seul

      Choisis l'option Search

      Une icône blanche et noire va s'afficher sur le bureau , il te servira à relancer le programme par la suite.
      Une autre rouge et noir te servira a désinstaller le prog a la fin de la désinfection.

      ? laisse travailler l'outil

      A l'apparition de la fenêtre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

      Un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

      ? Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'écran "COMPLETED"
      0
      1. Voici le rapport :

        http://www.cijoint.fr/cjlink.php?file=cj201005/cijdYSPPsL.txt
        0
        1. Bonjour
          ? Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
          mais cette fois-ci :

          ? choisis l'Option Clean

          Ton PC va redemarrer,

          Laisse travailler l'outil.

          En fin de scan la fenêtre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

          ? Colle le contenu dans ta réponse
          0
          1. Voici le rapport :

            ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤

            User : utilisateur (Administrateurs)
            Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
            Start at: 18:35:50 | 25/05/2010

            Intel(R) Pentium(R) D CPU 2.80GHz
            Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
            Internet Explorer 8.0.6001.18702
            Windows Firewall Status : Enabled
            AV : avast! Antivirus 5.0.83886625 [ Enabled | Updated ]

            C:\ -> Disque fixe local | 465,75 Go (367,56 Go free) | NTFS
            D:\ -> Disque CD-ROM
            F:\ -> Disque amovible
            G:\ -> Disque amovible
            H:\ -> Disque amovible
            I:\ -> Disque amovible

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\logonui.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
            C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\cisvc.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\system32\wbem\unsecapp.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\userinit.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\cmd.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\Program Files\Alwil Software\Avast5\setup\avast.setup
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\Program Files\List_Kill'em\ERUNT.EXE
            C:\Program Files\List_Kill'em\pv.exe

            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

            Quarantined & Deleted !! : C:\documents and settings\NetworkService\Application Data\qvjsge.dat
            Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadD500.exe
            Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadX800.exe
            Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadZ510.exe
            Quarantined & Deleted !! : C:\Program Files\WindowsUpdate
            Quarantined & Deleted !! : C:\WINDOWS\SET2D.tmp
            Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
            Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
            Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp

            Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
            Quarantined & Deleted !! : C:\Documents and Settings\utilisateur\LOCAL Settings\Temp\jre-6u20-windows-i586-iftw-rv.exe
            Quarantined & Deleted !! : C:\Documents and Settings\utilisateur\LOCAL Settings\Temp\IadHide4.dll

            =======
            Hosts :
            =======

            127.0.0.1 localhost

            ========
            Registry
            ========

            Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Run : msconfig
            Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
            Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
            Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
            Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2AA2FBF8-9C76-4E97-A226-25C5F4AB6358}
            Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2AA2FBF8-9C76-4E97-A226-25C5F4AB6358}
            =================
            Internet Explorer
            =================

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
            Local Page REG_SZ C:\WINDOWS\system32\blank.htm
            Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
            Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            Start Page REG_SZ https://www.google.com/?gws_rd=ssl
            Local Page REG_SZ C:\WINDOWS\system32\blank.htm
            Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

            ===============
            Security Center
            ===============

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
            FirstRunDisabled REG_DWORD 1 (0x1)
            AntiVirusDisableNotify REG_DWORD 0 (0x0)
            FirewallDisableNotify REG_DWORD 0 (0x0)
            UpdatesDisableNotify REG_DWORD 0 (0x0)
            AntiVirusOverride REG_DWORD 1 (0x1)
            FirewallOverride REG_DWORD 1 (0x1)

            ========
            Services
            =========

            Ndisuio : Start = 3
            SharedAccess : Start = 2
            wuauserv : Start = 2
            wscsvc : Start = 2

            ============
            Disk Cleaned
            anti-ver blaster : OK
            Prefetch cleaned
            ================

            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

            device: opened successfully
            user: MBR read successfully
            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
            kernel: MBR read successfully
            user & kernel MBR OK

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
            0
            1. toujours ce problème de bug ?
              En tout cas, cela ne provient pas du MBR (zone du disque dur), car le rapport le confirme
              0
              Précédent
              • 1
              • 2