Rapport malware, PC infecté...
Valou35
-
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité -
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité -
Bonjour,
j'ai un souci avec mon PC qui plante, les icones disparaissent et je dois donc l'éteindre.
j'ai fait une analyse avec Malware, voici le rapport:
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Version de la base de données: 5248
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
05/12/2010 15:39:02
mbam-log-2010-12-05 (15-39-01).txt
Type d'examen: Examen complet (C:\|D:\|E:\|G:\|)
Elément(s) analysé(s): 203102
Temps écoulé: 45 minute(s), 55 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 13
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 9
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fe5b2d9d-91b0-b04b-ac20-14a260769687} (Adware.ColorSoft) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OOO (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\OOO (Rogue.LivePlayer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live-Player (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{194c2254-4131-1233-e6f6-d1c1fed2c43e} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{194c2254-4131-1233-e6f6-d1c1fed2c43e} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{194C2254-4131-1233-E6F6-D1C1FED2C43E} (Adware.Adrotator) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\program files\dealio toolbar\IE\4.1\dealiotoolbarie.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\documents and settings\pierre\mes documents\shareaza downloads\u96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\dealio toolbar\widgihelper.exe (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\fast browser search\IE\searchguardplus.exe (PUP.Fbsearch) -> Not selected for removal.
c:\program files\fast browser search\IE\update.exe (PUP.Fbsearch) -> Not selected for removal.
c:\system volume information\_restore{3de29f27-0f2d-4ad0-8c1b-a02b46af2193}\RP964\A0098774.rbf (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3de29f27-0f2d-4ad0-8c1b-a02b46af2193}\RP964\A0098782.old (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\documents and settings\pierre\local settings\application data\ljxvb_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
c:\documents and settings\pierre\local settings\application data\ljxvb_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
J'ai donc supprimé les éléments infectés, est-ce-que je dois faire autre chose ou non?
Merci pour vos réponses...
j'ai un souci avec mon PC qui plante, les icones disparaissent et je dois donc l'éteindre.
j'ai fait une analyse avec Malware, voici le rapport:
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Version de la base de données: 5248
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
05/12/2010 15:39:02
mbam-log-2010-12-05 (15-39-01).txt
Type d'examen: Examen complet (C:\|D:\|E:\|G:\|)
Elément(s) analysé(s): 203102
Temps écoulé: 45 minute(s), 55 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 13
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 9
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fe5b2d9d-91b0-b04b-ac20-14a260769687} (Adware.ColorSoft) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OOO (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\OOO (Rogue.LivePlayer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live-Player (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{194c2254-4131-1233-e6f6-d1c1fed2c43e} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{194c2254-4131-1233-e6f6-d1c1fed2c43e} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{194C2254-4131-1233-E6F6-D1C1FED2C43E} (Adware.Adrotator) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\program files\dealio toolbar\IE\4.1\dealiotoolbarie.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\documents and settings\pierre\mes documents\shareaza downloads\u96.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files\dealio toolbar\widgihelper.exe (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\fast browser search\IE\searchguardplus.exe (PUP.Fbsearch) -> Not selected for removal.
c:\program files\fast browser search\IE\update.exe (PUP.Fbsearch) -> Not selected for removal.
c:\system volume information\_restore{3de29f27-0f2d-4ad0-8c1b-a02b46af2193}\RP964\A0098774.rbf (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3de29f27-0f2d-4ad0-8c1b-a02b46af2193}\RP964\A0098782.old (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\documents and settings\pierre\local settings\application data\ljxvb_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
c:\documents and settings\pierre\local settings\application data\ljxvb_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
J'ai donc supprimé les éléments infectés, est-ce-que je dois faire autre chose ou non?
Merci pour vos réponses...
A voir également:
- Rapport malware, PC infecté...
- Reinitialiser pc - Guide
- Pc lent - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Malwarebytes anti-malware - Télécharger - Antivirus & Antimalwares
- Double ecran pc - Guide
23 réponses
Re,
5 ans environ dit le tuto :
https://www.commentcamarche.net/informatique/composants/1447-erreur-de-bios-changer-la-pile-de-la-carte-mere/
Si tu ne t'en sent pas capable, trouve quelqu'un pour le faire.
5 ans environ dit le tuto :
https://www.commentcamarche.net/informatique/composants/1447-erreur-de-bios-changer-la-pile-de-la-carte-mere/
Si tu ne t'en sent pas capable, trouve quelqu'un pour le faire.
sur le rapport de ZHPDiag après redémarrage :
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: Modified
[MD5.4EED4383FFE1C3BDE940948B03F35C7E] - (.Spigot, Inc. - Application Updater.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe [386560]
G2 - GCE: Preference [User Data\Default] [bjeikeheijdjdfjbmknpefojickbkmom] Offerbox v.2.1.3128.64 (Activé)
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} . (.Ask.com - Ask.com Search Assistant.) (1, 0, 2, 4) -- C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} . (.Ask.com - Ask.com Search Assistant.) -- C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} . (.Pas de propriétaire - IE Toolbar Engine.) -- C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} . (.Ask.com - Ask Toolbar.) -- C:\Program Files\AskTBar\bar\4.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} . (.Ask.com - Ask Toolbar.) -- C:\Program Files\AskTBar\bar\4.bin\ASKTBAR.DLL
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} . (.Pas de propriétaire - IE Toolbar Engine.) -- C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O4 - HKLM\..\Run: [SearchSettings] . (.Spigot, Inc. - Search Settings.) -- C:\Program Files\Fichiers communs\Spigot\Search Settings\SearchSettings.exe
O4 - HKCU\..\Run: [ljxvb] c:\documents and settings\pierre\local settings\application data\ljxvb.exe (.not file.)
O4 - HKUS\S-1-5-21-1085031214-1637723038-725345543-1004\..\Run: [ljxvb] c:\documents and settings\pierre\local settings\application data\ljxvb.exe (.not file.)
O23 - Service: (Application Updater) . (.Spigot, Inc. - Application Updater.) - C:\Program Files\Application Updater\ApplicationUpdater.exe
O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- AskTBar Uninstall
O42 - Logiciel: Fast Browser Search (My Tattoons) - (.Make The Web Better, LLC.) [HKLM] -- TBSB07183.TBSB07183Toolbar
O42 - Logiciel: Favorit (ljxvb) - (.Pas de propriétaire.) [HKLM] -- ljxvb
[HKCU\Software\AppDataLow\HavingFunOnline]
[HKCU\Software\AppDataLow\Software\Search Settings] )
[HKCU\Software\OfferBox]
[HKCU\Software\PriceGong]
[HKCU\Software\TBSB07183]
[HKLM\Software\Application Updater]
[HKLM\Software\OfferBox]
[HKLM\Software\Search Settings]
O43 - CFD: 22/11/2010 - 15:14:08 ----D- C:\Program Files\Application Updater
O43 - CFD: 21/02/2008 - 16:22:12 ----D- C:\Program Files\AskTBar
O43 - CFD: 01/09/2009 - 21:23:54 ----D- C:\Program Files\Fast Browser Search
O43 - CFD: 15/06/2010 - 16:01:12 ----D- C:\Program Files\Live-Player
O43 - CFD: 19/03/2010 - 14:47:50 ----D- C:\Program Files\Search Toolbar
O43 - CFD: 25/10/2009 - 08:33:46 ----D- C:\Program Files\SGPSA
O64 - Services: CurCS - "C:\Program Files\Application Updater\ApplicationUpdater.exe (.not file.) - Application Updater (Application Updater) .(.Pas de propriétaire - Pas de description.) - LEGACY_APPLICATION_UPDATER
O69 - SBI: SearchScopes [HKCU] {D8A9CBD9-2096-4E08-8CEB-557FC7A3FCE1} - (Fast Browser Search) - http://www.fastbrowsersearch.com
SR - | Auto 22/10/2010 386560 | "C:\Program Files\Application Updater\ApplicationUpdater.exe (Application Updater) . (.Spigot, Inc..) - C:\Program Files\Application Updater\ApplicationUpdater.exe
A part ça, MBAM s'est occupé de tout !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: Modified
[MD5.4EED4383FFE1C3BDE940948B03F35C7E] - (.Spigot, Inc. - Application Updater.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe [386560]
G2 - GCE: Preference [User Data\Default] [bjeikeheijdjdfjbmknpefojickbkmom] Offerbox v.2.1.3128.64 (Activé)
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} . (.Ask.com - Ask.com Search Assistant.) (1, 0, 2, 4) -- C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} . (.Ask.com - Ask.com Search Assistant.) -- C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} . (.Pas de propriétaire - IE Toolbar Engine.) -- C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} . (.Ask.com - Ask Toolbar.) -- C:\Program Files\AskTBar\bar\4.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} . (.Ask.com - Ask Toolbar.) -- C:\Program Files\AskTBar\bar\4.bin\ASKTBAR.DLL
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} . (.Pas de propriétaire - IE Toolbar Engine.) -- C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O4 - HKLM\..\Run: [SearchSettings] . (.Spigot, Inc. - Search Settings.) -- C:\Program Files\Fichiers communs\Spigot\Search Settings\SearchSettings.exe
O4 - HKCU\..\Run: [ljxvb] c:\documents and settings\pierre\local settings\application data\ljxvb.exe (.not file.)
O4 - HKUS\S-1-5-21-1085031214-1637723038-725345543-1004\..\Run: [ljxvb] c:\documents and settings\pierre\local settings\application data\ljxvb.exe (.not file.)
O23 - Service: (Application Updater) . (.Spigot, Inc. - Application Updater.) - C:\Program Files\Application Updater\ApplicationUpdater.exe
O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- AskTBar Uninstall
O42 - Logiciel: Fast Browser Search (My Tattoons) - (.Make The Web Better, LLC.) [HKLM] -- TBSB07183.TBSB07183Toolbar
O42 - Logiciel: Favorit (ljxvb) - (.Pas de propriétaire.) [HKLM] -- ljxvb
[HKCU\Software\AppDataLow\HavingFunOnline]
[HKCU\Software\AppDataLow\Software\Search Settings] )
[HKCU\Software\OfferBox]
[HKCU\Software\PriceGong]
[HKCU\Software\TBSB07183]
[HKLM\Software\Application Updater]
[HKLM\Software\OfferBox]
[HKLM\Software\Search Settings]
O43 - CFD: 22/11/2010 - 15:14:08 ----D- C:\Program Files\Application Updater
O43 - CFD: 21/02/2008 - 16:22:12 ----D- C:\Program Files\AskTBar
O43 - CFD: 01/09/2009 - 21:23:54 ----D- C:\Program Files\Fast Browser Search
O43 - CFD: 15/06/2010 - 16:01:12 ----D- C:\Program Files\Live-Player
O43 - CFD: 19/03/2010 - 14:47:50 ----D- C:\Program Files\Search Toolbar
O43 - CFD: 25/10/2009 - 08:33:46 ----D- C:\Program Files\SGPSA
O64 - Services: CurCS - "C:\Program Files\Application Updater\ApplicationUpdater.exe (.not file.) - Application Updater (Application Updater) .(.Pas de propriétaire - Pas de description.) - LEGACY_APPLICATION_UPDATER
O69 - SBI: SearchScopes [HKCU] {D8A9CBD9-2096-4E08-8CEB-557FC7A3FCE1} - (Fast Browser Search) - http://www.fastbrowsersearch.com
SR - | Auto 22/10/2010 386560 | "C:\Program Files\Application Updater\ApplicationUpdater.exe (Application Updater) . (.Spigot, Inc..) - C:\Program Files\Application Updater\ApplicationUpdater.exe
A part ça, MBAM s'est occupé de tout !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
@Lyonnais92 :
C'est pas pour dire que je suis beaucoup plus fort quoi toi en informatique, et en décontamination. Mais tu m'excusera, car ce que tu recommandes de faire, et bé, il peut largement le faire tout seul. Pas besoin de "faire le pro".
Donc à plus, et j'espère que ce pauvre bougre pourra avoir un ordi en état de marche à la clé.
(Soit dit en passant, j'ai regardé le site que tu as dans ton profil. On dira que, bon... Moi qui ai quelque base en HTML et CSS, je pourrai faire mieu =) )
C'est pas pour dire que je suis beaucoup plus fort quoi toi en informatique, et en décontamination. Mais tu m'excusera, car ce que tu recommandes de faire, et bé, il peut largement le faire tout seul. Pas besoin de "faire le pro".
Donc à plus, et j'espère que ce pauvre bougre pourra avoir un ordi en état de marche à la clé.
(Soit dit en passant, j'ai regardé le site que tu as dans ton profil. On dira que, bon... Moi qui ai quelque base en HTML et CSS, je pourrai faire mieu =) )