Probleme suite a infection

david79000 -  
 archet9 -
Bonjour,

Voila depuis 2 jours que j'ai eu une alerte de mon antivirus (j'ai mis les fichiers infectés en quarantaines) lorsque j'ouvre une page internet soit cela ouvre une autre page ou bien cela m'amène vers un autre site qui n'a aucun rapport avec celui que je désire voir.

C'est pourquoi je voudrais savoir si mon système est sain ou pas.

Je vous poste mon rapport ZHP Diag :
http://www.cijoint.fr/cjlink.php?file=cj201010/cijhikpdcT.txt

Merci.

32 réponses

  • 1
  • 2
  1. archet9
     
    Salut,

    A la vue de tes "comportements" vis à vis du P2P:

    BitTorrent DNA PeerToPeer
    P4P PeerToPeer
    Bittorent PeerToPeer
    Shareaza PeerToPeer

    ==> Il serait déja pour le moins judicieux d'avoir un pc à jour !!!!!

    Dans un premier temps:

    * Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag en cliquant sur l'écusson vert)
    Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
    Copie/colle les lignes suivantes en gras et place les dans ZHPFix :

    MBRFix

    - Clique sur « Tous », puis sur « Nettoyer »
    - Copie/colle la totalité du rapport dans ta prochaine réponse
    Tuto :
    http://www.premiumorange.com/zeb-help-process/zhpfix.html
    0
  2. david79000
     
    voila le rapport :

    Rapport de ZHPFix 1.12.3211 par Nicolas Coolman, Update du 14/10/2010
    Fichier d'export Registre :
    Run by david at 17/10/2010 18:42:39
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Master Boot Record ==========
    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8639FEC5]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\atapi -> 0x8592e1f8
    Warning: possible MBR rootkit infection !
    user & kernel MBR OK
    Use "Recovery Console" command "fixmbr" to clear infection !

    Resultat après le fix :
    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK

    ========== Récapitulatif ==========
    1 : Master Boot Record

    End of the scan

    PS : par contre pour les peer to peer j'avais shareaza d'installer mais je l'ai supprimer dernierement et les autre je ne sais pas d'ou qu'ils peuvent provenir, peut tu m'aider pour les désinstaller completement ? Merci encore de ta réponse.
    0
  3. archet9
     
    " peut tu m'aider pour les désinstaller completement ?"

    ==> Déja via le panneau de config --> Programmes --> Désinstaller un programme....(sinon on verra autrement)

    Saches que ces logs ne sont dangereux que si on les utilise .....!!!!!

    1)
    Fais un scan avec cet antispyware :
    Malwarebytes + tutoriel

    Tu l'installes; mets le a jour...(onglet mise a jour)
    Click maintenant sur l'onglet recherche et coche la case :
    "Executer un examen rapide".
    Puis click sur "rechercher".
    Laisses le scanner le pc...
    A la fin du scan, clique sur Afficher les résultats
    Si des elements on ete trouvés :
    > click sur supprimer la selection.

    si il t'es demandé de redemarrer > click sur "oui".
    A la fin un rapport va s'ouvrir;
    sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
    Copies et colles le rapport stp.

    2)
    Un nouveau ZHPdiag stp....

    ......."contributeur sécurité".....
    0
  4. david79000
     
    J'ai télécharger et installer malwarebytes mais dès ke j'essaye de l'ouvrir rien ne se passe donc j'ai installer rkill et ça me met ça :

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.
    Ran as david on 17/10/2010 at 20:04:13.

    Services Stopped:

    Processes terminated by Rkill or while it was running:

    C:\Windows\system32\DllHost.exe
    C:\Users\david\Documents\Programme\probleme\rkill.com

    Rkill completed on 17/10/2010 at 20:04:23.

    Que dois je faire maintenant, malwarebytes ne veut toujours pas se lancer.

    * j'ai renommer rkill en winlogon comme cela est le rapport me donne ça :

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.
    Ran as david on 17/10/2010 at 20:28:58.

    Services Stopped:

    Processes terminated by Rkill or while it was running:

    C:\Users\david\Documents\Programme\probleme\winlogon.com

    Rkill completed on 17/10/2010 at 20:29:07.

    malwarebyte ne se lance toujours pas .
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. david79000
     
    j'ai redémarrer plusieurs fois en mode sans echec et mode sans echec réseau mais je n'arrive pas a lancer malwarebytes, j'ai meme essayer de le réinstaller, je ne sais plus quoi faire.
    0
  7. david79000
     
    le rapport me donne ça :

    RogueKiller V1.4.0 by Tigzy
    contact at www.sur-la-toile.com
    mail: tigzy44<at>hotmail<dot>fr
    Remontées: https://www.luanagames.com/index.fr.html

    Operating System: Windows Vista (6.0.6001 Service Pack 1) version 32 bits
    Mode: Scan

    Bad processes:

    Found:

    Finished

    RogueKiller V1.4.0 by Tigzy
    contact at www.sur-la-toile.com
    mail: tigzy44<at>hotmail<dot>fr
    Remontées: https://www.luanagames.com/index.fr.html

    Operating System: Windows Vista (6.0.6001 Service Pack 1) version 32 bits
    Mode: Remove

    Bad processes:

    Deregistred:

    Finished

    PS : je n'arrive toujours pas a lancer malwarebytes :/
    0
  8. archet9
     
    P'tain...de merde de satan...connerie...

    Insiste avec RKILLL

    Un bref écran noir t'indiquera que le tool s'est correctement exécuté, s'il ne lance pas
    change de lien de téléchargement en utilisant le suivant à partir d'ici:

    Rkill COM: Rkill COM:
    https://download.bleepingcomputer.com/grinler/rkill.com https://download.bleepingcomputer.com/grinler/rkill.com

    Rkill SCR: Rkill RCS:
    https://download.bleepingcomputer.com/grinler/rkill.scr https://download.bleepingcomputer.com/grinler/rkill.scr

    Rkill PIF: Rkill PIF:
    http://download.bleepingcomputer.com/grinler/rkill.pif
    http://download.bleepingcomputer.com/grinler/rkill.pif

    ....."contributeur sécurité".....Merci d'accepter mes doutes,mes incertitudes , mes interrogations ...
    0
  9. archet9
     
    dsl...dodo ce soir ...on poursuit demain soir....sauf si un autre helper prends la suite....
    0
  10. david79000
     
    bon sa me met ça :

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.
    Ran as david on 17/10/2010 at 21:58:01.

    Services Stopped:

    Processes terminated by Rkill or while it was running:

    C:\Windows\system32\DllHost.exe
    C:\Users\david\Documents\Programme\probleme\rkill.com

    Rkill completed on 17/10/2010 at 21:58:10.

    ensuite je l'ai refait et sa me met sa :

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.
    Ran as david on 17/10/2010 at 21:59:07.

    Services Stopped:

    Processes terminated by Rkill or while it was running:

    C:\Users\david\Documents\Programme\probleme\rkill.com

    Rkill completed on 17/10/2010 at 21:59:16.

    malwarebytes ne fonctionne tjours pas alors que j'ai insistéavec rkill, mon pc va passer par la fenetre...
    0
  11. archet9
     
    DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

    Télécharge List_Kill'em et enregistre le sur ton bureau

    http://sd-4.archive-host.com/membres/up/829108531491024/Mes_Tools/List_Killem_Install.exe

    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis choisis l'option Search
    un icone blanc et noir va s'afficher sur le bureau , il te servira à rappeler le programme si besoin.

    laisse travailler l'outil

    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
    0
  12. david79000
     
    Bonsoir,

    Voila le contenu du rapport :

    http://www.cijoint.fr/cjlink.php?file=cj201010/cijEo02oKX.txt
    0
  13. archet9
     
    Bonsoir à nouveau...

    Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
    mais cette fois-ci :

    choisis l'option clean
    ton PC va redemarrer,

    laisse travailler l'outil.

    en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

    colle le contenu dans ta reponse
    0
  14. david79000
     
    Voila le contenu du rapport :

    ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.1.0 ¤¤¤¤¤¤¤¤¤¤

    User : david (Administrateurs)
    Update on 19/10/2010 by g3n-h@ckm@n ::::: 14.30
    Start at: 21:31:21 | 20/10/2010

    Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz
    Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
    Internet Explorer 7.0.6001.18000
    Windows Firewall Status : Enabled

    C:\ -> Disque fixe local | 116,44 Go (17,15 Go free) [VistaOS] | NTFS
    D:\ -> Disque fixe local | 106,68 Go (25,55 Go free) [DATA] | NTFS
    E:\ -> Disque CD-ROM
    F:\ -> Disque CD-ROM

    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

    Quarantined & Deleted !! : C:\ProgramData\nvModes.001
    Quarantined & Deleted !! : C:\ProgramData\nvModes.dat
    Quarantined & Deleted !! : C:\Windows\IFinst27.exe

    Quarantined & Deleted !! : C:\Windows\Temp\DMI19B7.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI1A62.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI1AA1.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI2E.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI4385.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI445F.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI50ED.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI5205.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI533D.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI560B.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI730.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI7B66.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI80B.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI9AB8.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMI9CEA.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMID5F4.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\DMIFD80.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\gd30C0.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\gd94FE.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\gdA6DF.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\gdBF48.tmp
    Quarantined & Deleted !! : C:\Windows\Temp\JET8F15.tmp
    Quarantined & Deleted !! : C:\Users\david\AppData\Local\d3d9caps.dat
    Quarantined & Deleted !! : C:\Users\david\Local Settings\Temp\1.jpg
    Quarantined & Deleted !! : C:\Users\david\Local Settings\Temp\2.jpg
    Quarantined & Deleted !! : C:\Users\david\Local Settings\Temp\url.txt
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\24725850-8531-d78e-1c48-5b22d5d12285.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\5e910827-17c6-2e8f-eafc-e1f88f11e107.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\76b53f42-9611-b604-056b-6eaa2a19efa0.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\86b83ca0-26c4-8ef6-9944-adee15fe1e06.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\9dc270f9-7e13-5092-9bd5-b0c81df09d96.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\AdobeUpdater12345.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\converter.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\ec57928a-0b0f-d191-efc1-436537e76a8e.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\ijjiOptimizer.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\jre-6u13-windows-i586-p-iftw.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\jre-6u17-windows-i586-iftw-rv.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\jre-6u18-windows-i586-iftw-rv.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\lmvB7BD.tmp.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\msg90AD.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\SearchWithGoogleUpdate.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Second_Life_Updater.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Uninstall.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_0ebb.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_2e1b.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_3a67.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_68de.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_7822.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_80f7.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_aab7.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_bc4a.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\Update_c8b5.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\wlsetup-cvr.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\_is841F.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\_isC28C.exe
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\50340359.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\DefInstAction.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\FW_Register_Plugin_Action.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\QBackupInst.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\srtspse.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\srtspso.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\srtspsp.dat
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\tmp1.data
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\NGMDll.dll
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\NGMResource.dll
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\swt-win32-3349.dll
    Quarantined & Deleted !! : C:\Users\david\LOCAL Settings\Temp\unicows.dll
    Deleted !! : C:\$Recycle.bin\S-1-5-21-2671475529-2194066995-1880231523-1000\$I2M7FOT.txt
    Deleted !! : C:\$Recycle.bin\S-1-5-21-2671475529-2194066995-1880231523-1000\$R2M7FOT.txt

    ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

    127.0.0.1 localhost

    ¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

    Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
    Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
    Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
    Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
    Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
    Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}

    ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    Local Page = C:\WINDOWS\system32\blank.htm
    Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    Start Page = https://www.google.com/?gws_rd=ssl
    Local Page = C:\WINDOWS\system32\blank.htm
    Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

    ¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    cval = 1 ()
    UacDisableNotify = 0 (0x0)
    InternetSettingsDisableNotify = 0 (0x0)
    AutoUpdateDisableNotify = 0 (0x0)
    FirstRunDisabled = 1 ()
    AntiVirusDisableNotify = 0 (0x0)
    FirewallDisableNotify = 0 (0x0)
    UpdatesDisableNotify = 0 (0x0)
    AntiVirusOverride = 0 (0x0)
    FirewallOverride = 0 (0x0)

    ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

    Ndisuio : Start = 3
    EapHost : Start = 2
    Wlansvc : Start = 2
    SharedAccess : Start = 2
    windefend : Start = 2
    wuauserv : Start = 2
    wscsvc : Start = 2

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    Disk Cleaned
    anti-ver blaster : OK
    Prefetch cleaned
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    FEATURE_BROWSER_EMULATION | svchost :
    ====================================

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x863C0EC5]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\atapi -> 0x8592f1f8
    Warning: possible MBR rootkit infection !
    user & kernel MBR OK
    Use "Recovery Console" command "fixmbr" to clear infection !

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    0
  15. archet9
     
    Peux-tu lancer Malwarebytes maintenant ?
    0
  16. david79000
     
    Non je n'arrive toujours pas a le lancer pourtant je l'ai (encore une fois) re-télécharger et installer, mais y a rien a y faire ce satané programme ne veut pas se lancer.

    Je pose la question comme ça, n'y a-t-il pas un programme similaire car la je vois pas du tout comment faire.
    0
  17. archet9
     
    ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

    ---> Double-clique sur Combofix.exe

    ---> Installe la console de récupération si l'outil te le propose.

    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt
    0
  18. david79000
     
    bon, j'ai télécharger combofix, j'ai désactivé mon pare-feu et mon antivirus et quand je double-clik dessus j'arrive sur le fenètre pour exécuter le programme et je clik dessus mais rien ne se passe, la j'abandonne ça m'énerve :/
    0
  • 1
  • 2