VIRUS NUQEL sur windows 7

Steph 77 -  
 Steph 77 -
Bonjour,

Voilà j'ai attrapé le virus nuqel sur windows 7 et je ne peux plus accéder à internet (message pour me vendre un pack securité) ni lancer aucune application.

Quelqu'un peut il m'aider ?

J'ai vu que le pseudo "moment de grace" a deja combattu ce virus mais je ne sais si sa methodo s'applique à mon cas. De plus je ne sais pas interprete les resultats des opérations type ZHdiag, USBfix ....

Merci à vous.

Stephane

23 réponses

  • 1
  • 2
  1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    bonjour

    j'ai fais ca moi ?

    Télécharge ZHPDiag ( de Nicolas coolman ).
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html


    (outil de diagnostic)


    Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

    Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin ( vista )

    Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

    Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    0
  2. Steph 77
     
    Bonsoir,

    Voici avec un peu de delai :

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijkuf3uKV.txt

    Merci.

    Stephane
    0
  3. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ok

    tres infecté et surtout ton 64 bits n'est pas adapté aux outils de désinfection


    DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)


    Télécharge ici :List_Kill'em et enregistre le sur ton bureau

    http://sd-4.archive-host.com/membres/up/829108531491024/Mes_Tools/List_Killem_Install.exe

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."

    sur le raccourci sur ton bureau pour lancer l'installation

    Laisse coché :

    Executer List_Kill'em

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis le bouton TOOLS

    puis le bouton KILLPROXY

    poste le rapport


    ..............

    ensuite

    choisis l'option Search

    laisse travailler l'outil

    il se peut qu'une boite de dialogue s'ouvre , dans ce cas clique sur "ok" ou "Agree"

    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal ,c'est une recherche supplementaire de fichiers cachés , le programme n'est pas bloqué.

    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

    NE LE POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    Clique sur Parcourir et cherche le fichier ci-dessus.

    Clique sur Ouvrir.

    Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

    est ajouté dans la page.

    Copie ce lien dans ta réponse.

    Fais de même avec more.txt qui se trouve sur ton bureau
    0
  4. Steph 77
     
    Ok mje vais procéder a la manip mais je ne sais pas ou desactivé mon antivirus. Je ne sais meme pas quel est le programme (avast ?,...)
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Steph 77
     
    RE bonsoir,

    Voici les fichiers demandés :
    http://www.cijoint.fr/cjlink.php?file=cj201009/cijg5AoF99.txt

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijHCLbnjJ.txt

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijI2lcCTo.txt

    Merci
    0
  7. Steph 77
     
    Je crois que j'ai mis 2 fois le meme.

    Voici le 3ème (fichier more)
    http://www.cijoint.fr/cjlink.php?file=cj201009/cijpomVMvX.txt

    Stephane
    0
  8. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ok

    1)

    Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
    mais cette fois-ci :

    choisis l'option CLEAN

    laisse travailler l'outil.

    en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

    colle le contenu dans ta reponse

    ......................

    2)

    Téléchargez MalwareByte's Anti-Malware (que tu pourras garder)

    https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

    . Enregistres le sur le bureau
    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
    . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
    . Une fois la mise à jour terminé
    . Rend-toi dans l'onglet, Recherche
    . Sélectionnes Exécuter un examen complet (examen assez long)
    . Cliques sur Rechercher
    . Le scan démarre.
    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    . Cliques sur Ok pour poursuivre.
    . Si des malwares ont été détectés, clique sur Afficher les résultats
    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
    . Rends toi dans l'onglet rapport/log
    . Tu cliques dessus pour l'afficher, une fois affiché
    . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
    . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
    . tu cliques droit dans le cadre de la reponse et coller

    Si tu as besoin d'aide regarde ces tutoriels :
    Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

    0
  9. Steph 77
     
    Bonjour "moment de grace",

    Voici le rapport Kill'em demandé :

    ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.3 ¤¤¤¤¤¤¤¤¤¤

    User : Compaq (Administrateurs)
    Update on 09/09/2010 by g3n-h@ckm@n ::::: 23.15
    Start at: 21:58:30 | 10/09/2010

    Intel(R) Pentium(R) 4 CPU 2.93GHz
    Microsoft Windows 7 Édition Intégrale (6.1.7600 64-bit) #
    Internet Explorer 8.0.7600.16385
    Windows Firewall Status : Disabled
    AV : avast! antivirus 4.8.1229 [VPS 100303-0] 4.8.1229 [ Enabled | Updated ]

    A:\ -> Lecteur de disquettes 3 ½ pouces
    B:\ -> Lecteur de disquettes 3 ½ pouces | 1,39 Mo (0,16 Mo free) | FAT
    C:\ -> Disque fixe local | 226,88 Go (26,86 Go free) [PRESARIO] | NTFS
    D:\ -> Disque fixe local | 5,99 Go (2,34 Go free) [PRESARIO_RP] | FAT32
    E:\ -> Disque CD-ROM | 4,22 Go (0 Mo free) [PCM2010] | CDFS
    G:\ -> Disque amovible | 3,83 Go (2,21 Go free) [MEMUP] | FAT32
    I:\ -> Disque amovible
    J:\ -> Disque amovible
    K:\ -> Disque amovible
    L:\ -> Disque amovible

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)

    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe ----3880 Ko
    C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe ----428 Ko
    C:\Users\Compaq\AppData\Local\Temp\doa546.exe ----16476 Ko
    C:\Users\Compaq\AppData\Local\Temp\install.exe ----7180 Ko
    C:\Windows\sysedit.exe ----8768 Ko
    C:\Users\Compaq\AppData\Local\Temp\wininst.exe ----6012 Ko
    C:\Windows\avp.exe ----6428 Ko
    C:\Users\Compaq\AppData\Local\Temp\exs57zmh.exe ----6248 Ko
    C:\Program Files (x86)\FinePixViewer\QuickDCF2.exe ----5484 Ko
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ----3844 Ko
    C:\Users\Compaq\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe ----6344 Ko
    C:\Users\Compaq\AppData\Local\Temp\install.exe ----4656 Ko
    C:\Users\Compaq\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe ----3712 Ko
    C:\Windows\sysedit.exe ----3668 Ko
    C:\Users\Compaq\AppData\Local\Temp\geurge.exe ----18060 Ko
    C:\Users\Compaq\AppData\Local\Temp\wininst.exe ----3712 Ko
    C:\Windows\avp.exe ----3704 Ko
    C:\Users\Compaq\AppData\Local\Temp\exs57zmh.exe ----6716 Ko
    C:\Program Files (x86)\Spyware Doctor\pctsTray.exe ----2212 Ko
    C:\Users\Compaq\AppData\Local\Temp\x1z79jyz.exe ----2788 Ko
    C:\Windows\SysWOW64\cmd.exe ----3436 Ko
    C:\Users\Compaq\AppData\Roaming\ATI\CRTUPL~1\msftdm.exe ----5036 Ko
    C:\Users\Compaq\AppData\Roaming\ATI\CRTUPL~1\msftdm32.exe ----30920 Ko
    C:\Windows\SysWOW64\cmd.exe ----3784 Ko
    C:\Program Files (x86)\List_Kill'em\ERUNT.EXE ----6708 Ko
    C:\Program Files (x86)\List_Kill'em\pv.exe ----5360 Ko

    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

    Quarantined & Deleted !! : C:\Program Files (x86)\Ask.com
    Quarantined & Deleted !! : C:\Windows\avp.exe
    Quarantined & Deleted !! : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

    Quarantined & Deleted !! : C:\Windows\system32\drivers\protect.sys
    Quarantined & Deleted !! : C:\Windows\Temp\TS_57C1.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_58CB.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_5BB8.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_5E29.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_66A2.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_6D67.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_6F2C.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_7F72.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_8AC9.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\TS_8D78.tmp
    Quarantined & Deleted !! : C:\Users\Compaq\AppData\Local\GDIPFONTCACHEV1.DAT
    Quarantined & Deleted !! : C:\Users\Compaq\AppData\LocalLow\AskToolbar
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\6208,649.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\9786,938.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\B33C11F5-3A11-4f1e-85E4-C3CABE52C369.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\doa546.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\FP_PL_MSI_INSTALLER.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\geurge.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\hybwfj.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\iei7uh52tb082bo.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\ose00000.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\p8en6k5m.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\ptidi3mc.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\Toolbar.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\x1z79jyz.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\z0ytyfw.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\_is3C2B.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\_isBCAA.exe
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\catchme.dll
    Quarantined & Deleted !! : C:\Users\Compaq\LOCAL Settings\Temp\fxdecod1.dll

    ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

    127.0.0.1 localhost

    ¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

    Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Run : ewrgetuj
    Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar : {D4027C7F-154A-4066-A1AD-4243D8127440}
    Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {D4027C7F-154A-4066-A1AD-4243D8127440}
    Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer : winid
    Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks : {00000000-6E41-4FD3-8538-502F5495E5FC}
    Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoFolderOptions
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoActiveDesktop
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoActiveDesktopChanges
    Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System : DisableRegistryTools
    Deleted : "HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}"
    Deleted : "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
    Deleted : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}"
    Deleted : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}"
    Deleted : HKCR\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}
    Deleted : HKCR\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}
    Deleted : HKCR\GenericAskToolbar.ToolbarWnd
    Deleted : HKCR\GenericAskToolbar.ToolbarWnd.1
    Deleted : HKCR\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
    Deleted : HKCU\software\appdatalow\AskToolbarInfo
    Deleted : HKCU\software\appdatalow\software\AskToolbar
    Deleted : HKCU\software\Ask.com
    Deleted : HKCU\Software\Conduit
    Deleted : HKLM\software\classes\appid\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
    Deleted : HKLM\software\classes\appid\GenericAskToolbar.DLL
    Deleted : HKLM\software\classes\installer\Products\A28B4D68DEBAA244EB686953B7074FEF
    Deleted : HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
    Deleted : HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
    Deleted : HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
    Deleted : HKLM\software\microsoft\windows\currentversion\uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

    ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    Local Page = C:\WINDOWS\system32\blank.htm
    Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    Start Page = https://www.google.com/?gws_rd=ssl
    Local Page = C:\WINDOWS\system32\blank.htm
    Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

    ¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    FirstRunDisabled = 1 ()
    AntiVirusDisableNotify = 0 (0x0)
    FirewallDisableNotify = 0 (0x0)
    UpdatesDisableNotify = 0 (0x0)
    AntiVirusOverride = 0 (0x0)
    FirewallOverride = 0 (0x0)

    ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

    Ndisuio : Start = 3
    EapHost : Start = 2
    Wlansvc : Start = 2
    SharedAccess : Start = 2
    windefend : Start = 2
    wuauserv : Start = 2
    wscsvc : Start = 2

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    Disk Cleaned
    anti-ver blaster : OK
    Prefetch cleaned
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    FEATURE_BROWSER_EMULATION | svchost :
    ====================================

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: error reading MBR

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    Et puis le rapport malaware :

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4591

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    11/09/2010 06:31:38
    mbam-log-2010-09-11 (06-31-38).txt

    Type d'examen: Examen complet (C:\|D:\|)
    Elément(s) analysé(s): 365948
    Temps écoulé: 1 heure(s), 18 minute(s), 40 seconde(s)

    Processus mémoire infecté(s): 8
    Module(s) mémoire infecté(s): 1
    Clé(s) du Registre infectée(s): 3
    Valeur(s) du Registre infectée(s): 14
    Elément(s) de données du Registre infecté(s): 1
    Dossier(s) infecté(s): 3
    Fichier(s) infecté(s): 39

    Processus mémoire infecté(s):
    C:\Users\Compaq\AppData\Local\Temp\exs57zmh.exe (Trojan.Downloader) -> Unloaded process successfully.
    C:\Users\Compaq\AppData\Local\Temp\exs57zmh.exe (Trojan.Downloader) -> Unloaded process successfully.
    C:\Users\Compaq\AppData\Roaming\ATI\crtupldll42\msftdm.exe (Trojan.Agent) -> Unloaded process successfully.
    C:\Users\Compaq\AppData\Roaming\ATI\crtupldll42\msftdm32.exe (Trojan.Agent) -> Unloaded process successfully.
    C:\Users\Compaq\AppData\Local\Temp\install.exe (Trojan.Downloader) -> Unloaded process successfully.
    C:\Windows\sysedit.exe (Trojan.Downloader) -> Unloaded process successfully.
    C:\Users\Compaq\AppData\Local\Temp\wininst.exe (Trojan.Downloader) -> Unloaded process successfully.
    C:\Users\Compaq\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe (Malware.Packer.Gen) -> Unloaded process successfully.

    Module(s) mémoire infecté(s):
    C:\Users\Compaq\AppData\Roaming\ATI\crtupldll42\msftldr.dll (Trojan.Agent) -> Delete on reboot.

    Clé(s) du Registre infectée(s):
    HKEY_CURRENT_USER\Software\MSoftware (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\protect (Rootkit.Agent) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvenzkfgnvf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvenzkfgnvf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvenzkfgota (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvenzkfgota (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqutc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqutc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvenzkfgsre (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvenzkfgsre (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\poaxtpsb (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpe (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpe (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqqyc (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqqyc (Trojan.Agent) -> Quarantined and deleted successfully.

    Elément(s) de données du Registre infecté(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Dossier(s) infecté(s):
    C:\Program Files (x86)\Ecobar (Adware.Ecobar) -> Quarantined and deleted successfully.
    C:\sysmon\bufb13086 (P2P.Downloader) -> Quarantined and deleted successfully.
    C:\sysmon\flvdirect (Adware.Dropper) -> Quarantined and deleted successfully.

    Fichier(s) infecté(s):
    C:\Users\Compaq\AppData\Local\Temp\exs57zmh.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Roaming\ATI\crtupldll42\msftdm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Roaming\ATI\crtupldll42\msftldr.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Roaming\ATI\crtupldll42\msftdm32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\install.exe (Trojan.Downloader) -> Delete on reboot.
    C:\Windows\sysedit.exe (Trojan.Downloader) -> Delete on reboot.
    C:\Users\Compaq\AppData\Local\Temp\wininst.exe (Trojan.Downloader) -> Delete on reboot.
    C:\Users\Compaq\AppData\Local\lecnscfpt\uxucxrlshdw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    C:\Kill'em\Quarantine\avp.exe.Kill'em (Trojan.Downloader) -> Delete on reboot.
    C:\Kill'em\Quarantine\doa546.exe.Kill'em (Backdoor.Bot) -> Delete on reboot.
    C:\Kill'em\Quarantine\geurge.exe.Kill'em (Trojan.Agent.Gen) -> Delete on reboot.
    C:\Kill'em\Quarantine\hybwfj.exe.Kill'em (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    C:\Kill'em\Quarantine\iei7uh52tb082bo.exe.Kill'em (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Kill'em\Quarantine\protect.sys.Kill'em (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\Kill'em\Quarantine\ptidi3mc.exe.Kill'em (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Kill'em\Quarantine\z0ytyfw.exe.Kill'em (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\sysmon\bufb13086\cubmj05012.exe (Trojan.VB.Downloader) -> Quarantined and deleted successfully.
    C:\sysmon\bufb13086\elno8207.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
    C:\sysmon\bufb13086\fppet7848.exe (Adware.Dropper) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\3990d079.tmp (Spyware.Zbot) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\iexplorer.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\~TMCD1E.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\Rar$EX00.001\keymaker-setup.exe (P2P.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\Rar$EX00.001\Setup.exe (P2P.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
    C:\Users\Compaq\Desktop\Installation\Microsoft Office 2007\Keygen Office 2007.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
    C:\Users\Compaq\Desktop\Installation\nero-8.2.8.0_europe_lite\keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Compaq\Desktop\Installation\Winrar\keygenpatch.exe (Trojan.Patcher) -> Quarantined and deleted successfully.
    C:\Windows\System32\m9n1y.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
    C:\Windows\SysWOW64\m9n1y.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
    C:\Windows.old\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\ShprInstaller.exe (Adware.Shopper) -> Quarantined and deleted successfully.
    C:\Windows.old\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\ZAN21F.exe (Adware.Seekmo) -> Quarantined and deleted successfully.
    C:\Windows.old\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\nsv222.tmp\Install.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
    C:\Windows.old\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\nsv222.tmp\Resource.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
    C:\Windows.old\Program Files\EoRezo\EoEngine.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
    C:\Windows.old\Program Files\EoRezo\EoAdv\EoAdv.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
    C:\Windows.old\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (Adware.Shopper) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinUpdate.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Compaq\AppData\Local\Temp\skaioejiesfjoee.tmp (Malware.Trace) -> Quarantined and deleted successfully.

    @+
    stephane
    0
  10. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    vu

    vide la quarantaine de MBAM

    puis

    Fais un nouveau rapport ZHPdiag stp

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    si soucis avec ci joint. fr

    => utiliser https://www.cjoint.com/
    => utiliser http://ww38.toofiles.com/fr/oip/documents/txt/av.html
    0
  11. Steph 77
     
    La quaranaine est vidée.

    voici le rapport demandé :
    http://www.cijoint.fr/cjlink.php?file=cj201009/cijr2qr3xi.txt

    Merci
    0
  12. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ok

    * Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: Modified
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: Modified
    [MD5.101C553D501BF206CE3B84E6B3EDF952] - (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe [60004]
    [MD5.101C553D501BF206CE3B84E6B3EDF952] - (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe [60004]
    [MD5.101C553D501BF206CE3B84E6B3EDF952] - (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe [60004]
    O4 - HKLM\..\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe
    O4 - HKLM\..\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe
    O4 - HKLM\..\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe
    O4 - HKLM\..\Run: [Mqpe] C:\Windows\avp.exe (.not file.)
    O4 - HKCU\..\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe
    O4 - HKCU\..\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe
    O4 - HKCU\..\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe
    O4 - HKCU\..\Run: [Mqpe] C:\Windows\avp.exe (.not file.)
    O4 - HKLM\..\Wow6432Node\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe
    O4 - HKLM\..\Wow6432Node\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe
    O4 - HKLM\..\Wow6432Node\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe
    O4 - HKLM\..\Wow6432Node\Run: [Mqpe] C:\Windows\avp.exe (.not file.)
    O4 - HKLM\..\policies\Explorer\Run: [lt4tmf] C:\Users\Compaq\AppData\Local\Temp\doa546.exe (.not file.)
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [Mqpe] C:\Windows\avp.exe (.not file.)
    [HKCU\Software\AskToolbar]
    O41 - Driver: zlwrvlrxegncj7 (zlwrvlrxegncj7) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\zlwrvlrxegncj7.sys
    O58 - SDL:[MD5.61FFF3CC36241826CB2D814BE1F58F99] - 10/09/2010 - 19:35:16 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysWOW64\drivers\zlwrvlrxegncj7.sys


    Puis Lance ZHPFix depuis le raccourci du bureau .

    * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

    * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

    Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

    Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

    Copie/Colle le rapport à l'écran dans ton prochain message

    ( ce rapport est sauvegardé dans ce dossier C:\Program files\ZHPDiag\ZHPFixReport.txt )
    0
  13. Steph 77
     
    Voici le rapport ZHPfix

    Rapport de ZHPFix v1.12.3148 par Nicolas Coolman, Update du 09/09/2010
    Fichier d'export Registre :
    Run by Compaq at 11/09/2010 07:56:03
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Récapitulatif ==========

    End of the scan
    0
  14. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    recommence zhpfix

    ca n'a pas fonctionné
    0
  15. Steph 77
     
    Effectivement j'avais oublie un clic sur "tous"

    voici :
    Rapport de ZHPFix v1.12.3148 par Nicolas Coolman, Update du 09/09/2010
    Fichier d'export Registre :
    Run by Compaq at 11/09/2010 08:12:23
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Processus mémoire ==========
    C:\Users\Compaq\AppData\Local\Temp\install.exe [60004] => Supprimé et mis en quarantaine
    C:\Windows\sysedit.exe [60004] => Fichier supprimé au reboot
    C:\Users\Compaq\AppData\Local\Temp\wininst.exe [60004] => Fichier supprimé au reboot

    ========== Clé(s) du Registre ==========
    HKCU\Software\AskToolbar => Clé supprimée avec succès
    O41 - Driver: zlwrvlrxegncj7 (zlwrvlrxegncj7) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\zlwrvlrxegncj7.sys => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O4 - HKLM\..\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe => Valeur supprimée avec succès
    O4 - HKLM\..\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe => Valeur supprimée avec succès
    O4 - HKLM\..\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe => Valeur supprimée avec succès
    O4 - HKLM\..\Run: [Mqpe] C:\Windows\avp.exe (.not file.) => Valeur supprimée avec succès
    O4 - HKCU\..\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe => Valeur supprimée avec succès
    O4 - HKCU\..\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe => Valeur supprimée avec succès
    O4 - HKCU\..\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe => Valeur supprimée avec succès
    O4 - HKCU\..\Run: [Mqpe] C:\Windows\avp.exe (.not file.) => Valeur supprimée avec succès
    O4 - HKLM\..\Wow6432Node\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe => Valeur absente
    O4 - HKLM\..\Wow6432Node\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe => Valeur absente
    O4 - HKLM\..\Wow6432Node\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe => Valeur absente
    O4 - HKLM\..\Wow6432Node\Run: [Mqpe] C:\Windows\avp.exe (.not file.) => Valeur absente
    O4 - HKLM\..\policies\Explorer\Run: [lt4tmf] C:\Users\Compaq\AppData\Local\Temp\doa546.exe (.not file.) => Valeur supprimée avec succès
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [LvenZkfgsre] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\wininst.exe => Valeur absente
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [Mqutc] . (.Microsoft Corporation - System Service.) -- C:\Windows\sysedit.exe => Valeur absente
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [LvenZkfgota] . (.Microsoft Corporation - System Service.) -- C:\Users\Compaq\AppData\Local\Temp\install.exe => Valeur absente
    O4 - HKUS\S-1-5-21-737450625-1110077367-1331746390-1001\..\Run: [Mqpe] C:\Windows\avp.exe (.not file.) => Valeur absente

    ========== Elément(s) de donnée du Registre ==========
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: Modified => Donnée supprimée avec succès
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: Modified => Donnée supprimée avec succès

    ========== Fichier(s) ==========
    c:\windows\avp.exe => Fichier supprimé au reboot
    c:\users\compaq\appdata\local\temp\doa546.exe => Fichier supprimé au reboot

    ========== Récapitulatif ==========
    3 : Processus mémoire
    2 : Clé(s) du Registre
    17 : Valeur(s) du Registre
    2 : Elément(s) de donnée du Registre
    2 : Fichier(s)

    End of the scan
    0
  16. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    redemarre le pc

    Fais un nouveau rapport ZHPdiag stp

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    si soucis avec ci joint. fr

    => utiliser https://www.cjoint.com/
    => utiliser http://ww38.toofiles.com/fr/oip/documents/txt/av.html

    CONTRIBUTEUR SECURITE

    Désinfection = diagnostic + traitement + finalisation
    "Restez" jusqu'au bout...merci
    0
  17. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    * Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: Modified
    O58 - SDL:[MD5.61FFF3CC36241826CB2D814BE1F58F99] - 10/09/2010 - 19:35:16 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysWOW64\drivers\zlwrvlrxegncj7.sys


    Puis Lance ZHPFix depuis le raccourci du bureau .

    * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

    * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

    Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

    Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

    Copie/Colle le rapport à l'écran dans ton prochain message

    ( ce rapport est sauvegardé dans ce dossier C:\Program files\ZHPDiag\ZHPFixReport.txt )
    0
  18. Steph 77
     
    voici

    Rapport de ZHPFix v1.12.3148 par Nicolas Coolman, Update du 09/09/2010
    Fichier d'export Registre :
    Run by Compaq at 11/09/2010 08:36:21
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Elément(s) de donnée du Registre ==========
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: Modified => Donnée supprimée avec succès

    ========== Fichier(s) ==========
    c:\windows\syswow64\drivers\zlwrvlrxegncj7.sys => Fichier supprimé au reboot

    ========== Récapitulatif ==========
    1 : Elément(s) de donnée du Registre
    1 : Fichier(s)

    End of the scan
    0
  19. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ok

    redémarre le pc et dis moi ensuite comment il va
    0
  20. Steph 77
     
    Le PC a L'air de bien se comporter.

    J'ai reactivier l'alerte de modification paramètres windows
    J'ai réactivé le pare feu.

    Le net fonctionne et les programmes s'ouvrent correctement.
    Pas de message d'erreur particulier.

    Tout semble normal.

    Est ce fini ?

    En tous cas Merci.
    Stephane
    0
  • 1
  • 2