Infection par un virus

Bonjour,



Le PC est très ralenti et des programmes réagissent anormalement (par ex fréquents problèmes de convertisseur dans word sur des fichiers qui ne présentaient aucune anomalie)

Je poste ci-joint le rapport Malewarebyte'antimalware

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5510

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

13/01/2011 11:10:01
mbam-log-2011-01-13 (11-10-01).txt

Type d'examen: Examen rapide
Elément(s) analysé(s): 142172
Temps écoulé: 7 minute(s), 31 seconde(s)

Processus mémoire infecté(s): 2
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 7
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3

Processus mémoire infecté(s):
c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> 1568 -> Not selected for removal.
c:\program files\fichiers communs\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> 3856 -> Not selected for removal.

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Not selected for removal.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio) -> Value: APPLICATIONUPDATER.EXE -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchSettings (PUP.Dealio) -> Value: SearchSettings -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\FICHIERS COMMUNS\SPIGOT\SEARCH SETTINGS\SEARCHSETTINGS.EXE (PUP.Dealio) -> Value: SEARCHSETTINGS.EXE -> Not selected for removal.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> Not selected for removal.
c:\program files\pdfforge toolbar\IE\4.1\pdfforgetoolbarie.dll (PUP.Dealio) -> Not selected for removal.
c:\program files\fichiers communs\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> Not selected for removal.

Merci de votre aide,

7 réponses

  1. Contributeur sécurité
    Salut

    Tu n'as rien supprimé dans MBAM, c'est normal?
    0
    1. Bonjour

      Après avoir exécuté MBAM je coche "supprimer la sélection" mais manifestement les fichiers infectés reviennent.
      J'ai refait un examen complet (le 1er etait rapide) et voilà le rapport:

      Malwarebytes' Anti-Malware 1.50.1.1100
      www.malwarebytes.org

      Version de la base de données: 5510

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18702

      13/01/2011 16:17:48
      mbam-log-2011-01-13 (16-10-34).txt

      Type d'examen: Examen complet (C:\|)
      Elément(s) analysé(s): 228506
      Temps écoulé: 1 heure(s), 6 minute(s), 33 seconde(s)

      Processus mémoire infecté(s): 2
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 7
      Valeur(s) du Registre infectée(s): 5
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 8

      Processus mémoire infecté(s):
      c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> 1608 -> No action taken.
      c:\program files\fichiers communs\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> 3828 -> No action taken.

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio) -> Value: APPLICATIONUPDATER.EXE -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchSettings (PUP.Dealio) -> Value: SearchSettings -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\FICHIERS COMMUNS\SPIGOT\SEARCH SETTINGS\SEARCHSETTINGS.EXE (PUP.Dealio) -> Value: SEARCHSETTINGS.EXE -> No action taken.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> No action taken.
      c:\program files\pdfforge toolbar\IE\4.1\pdfforgetoolbarie.dll (PUP.Dealio) -> No action taken.
      c:\program files\pdfforge toolbar\widgihelper.exe (PUP.Dealio) -> No action taken.
      c:\system volume information\_restore{6b3f7072-781b-403b-9914-dd21b0408faa}\RP505\A0087515.rbf (PUP.Dealio) -> No action taken.
      c:\system volume information\_restore{6b3f7072-781b-403b-9914-dd21b0408faa}\RP505\A0087517.rbf (PUP.Dealio) -> No action taken.
      c:\system volume information\_restore{6b3f7072-781b-403b-9914-dd21b0408faa}\RP505\A0087525.old (PUP.Dealio) -> No action taken.
      c:\system volume information\_restore{6b3f7072-781b-403b-9914-dd21b0408faa}\RP505\A0087526.old (PUP.Dealio) -> No action taken.
      c:\program files\fichiers communs\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> No action taken.

      Merci de ton aide
      0
      1. Je viens de refaire un examen rapide MBM. J'ai fait attention de cocher la sélection (il est possible que j'ai oublié ça auparavant je suis très tête en l'air)

        Malwarebytes' Anti-Malware 1.50.1.1100
        www.malwarebytes.org

        Version de la base de données: 5510

        Windows 5.1.2600 Service Pack 3
        Internet Explorer 8.0.6001.18702

        14/01/2011 11:46:57
        mbam-log-2011-01-14 (11-46-57).txt

        Type d'examen: Examen rapide
        Elément(s) analysé(s): 142028
        Temps écoulé: 5 minute(s), 55 seconde(s)

        Processus mémoire infecté(s): 2
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 7
        Valeur(s) du Registre infectée(s): 5
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 3

        Processus mémoire infecté(s):
        c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> 1648 -> Unloaded process successfully.
        c:\program files\fichiers communs\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> 4024 -> Unloaded process successfully.

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio) -> Value: APPLICATIONUPDATER.EXE -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B922D405-6D13-4A2B-AE89-08A030DA4402} (PUP.Dealio) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchSettings (PUP.Dealio) -> Value: SearchSettings -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\FICHIERS COMMUNS\SPIGOT\SEARCH SETTINGS\SEARCHSETTINGS.EXE (PUP.Dealio) -> Value: SEARCHSETTINGS.EXE -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> Quarantined and deleted successfully.
        c:\program files\pdfforge toolbar\IE\4.1\pdfforgetoolbarie.dll (PUP.Dealio) -> Quarantined and deleted successfully.
        c:\program files\fichiers communs\Spigot\search settings\searchsettings.exe (PUP.Dealio) -> Quarantined and deleted successfully.
        0
        1. Contributeur sécurité
          C'est mieux :)

          * Télécharge ZHPDiag
          Capture

          * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
          * Sous vista/seven, si un message d'erreur apparait , clique droit => exécuter en tant qu'admin
          * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
          * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
          * Heberge le rapport ici: cijoint et colle le lien dans la réponse
          0
      2. Bonsoir

        Lorsque je lance le diagnostic ZHP Diag le diagnostic commence normalement puis se plante sur
        "DOS//Devices" en détaillant les disques analysés.

        J'ai un message d'erreur :

        "WINDOWS PAS DE DISQUE
        Exception Processing
        Message c00000013 Parameters 75afbf7c 4 75afbf7c 75afbf7c"

        Merci de ton aide,
        0
        1. J'ajoute une précision :

          je ne peux pas poster le rapport car le PC plante et m'affiche ce message.

          Sur le bas de la fiche diagnostic de ZHP Diag il y a le message suivant :
          "Mount Points 2 Shell Key (MPSK) (051)
          c:/Windows/S32/ZOUyoh.exe (not file)"
          0
          1. Contributeur sécurité
            ok

            Brancher les lecteurs externes (Clé USB, Disque dur, ...) susceptibles
            d'avoir été infectés

            Télécharger USBFix

            - Lancer USBFix.exe
            - Choisir Suppression
            - Puis ok
            - Patienter pendant la détection- Un fichier texte s'ouvre, fichier => enregistrer sous
            - laisser le nom par défaut, enregistrer sur le bureau
            - copier coller le contenu du fichier texte dans la fenetre de réponse
            Contributeur SECURITE *** Développeur de RogueKiller ***
            Pas de rapports par MP, hébergez les sur www.cijoint.fr. Pas de désinfection par MP, merci d'ouvrir un fil
            0
            1. Bonsoir

              J'ai lancé USBFIX.exe Suppression Ok
              Après analyse il m'affiche le bureau Windows vide et le PC ne réagit plus.
              Je dois relancer l'UC pour le faire redémarrer.

              Je retrouve dans USBFIX le rapport suivant (l'analyse s'arrête à J: et la clé USB est sur L:) :

              ############################## | UsbFix 7.038 | [Listing]

              Utilisateur: Gérard (Administrateur) # DELL-GERARD [ ]
              Mis à jour le 14/01/2011 par El Desaparecido / C_XX
              Lancé à 17:40:11 | 18/01/2011
              Site Web: http://www.teamxscript.org
              Contact: eldesaparecido@teamxscript.org

              CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz
              CPU 2: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz
              Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702

              Pare-feu Windows: Activé
              Antivirus: avast! Antivirus 5.0.83952480 [Enabled | Updated]
              Firewall: avast! Antivirus 5.0.83952480 [(!) Disabled]
              RAM -> 2037 Mo
              C:\ (%systemdrive%) -> Disque fixe # 288 Go (182 Go libre(s) - 63%) [] # NTFS
              D:\ -> Disque fixe # 233 Go (184 Go libre(s) - 79%) [Ancien Ordi] # NTFS
              E:\ -> Disque fixe # 466 Go (318 Go libre(s) - 68%) [IOMEGA_HDD] # FAT32
              I:\ -> Disque fixe # 10 Go (169 Mo libre(s) - 2%) [RECOVERY] # NTFS
              J:\ -> CD-ROM

              ################## | Listing |

              Pas moyen de faire un diagnostic complet.
              Merci de ton aide.
              0