Windows Restore Je vous en supplis, aidez moi

Fermé
Bonjour,

Bonjour,
S'il vous plais aidé moi , je peux plus rien faire et je suis nul en informatique , j'arrive pas a quitté windows restore et si j'le suprime pas vite je vais me faire tué (c'est pas mon ordinateur)
Je vous ensupplis.

7 réponses

  1. salut ^^Marie^^

    on peut Fermer....thx
    1
    1. salut

      desactive tes protections puis enregistre ceci sur ton bureau

      Pre_Scan

      si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

      une fois telechargé lance-le , laisse faire le scan puis colle le contenu de " rapport.txt" qui apparaitra à son terme , sur le bureau.

      si l'outil semble ne pas avoir fonctionné clique plusieurs fois très rapidement dessus
      0
      1. Bonjour,

        Je suis également infecté par le logiciel malveillant windows restore. Par contre moi j'ai accès à internet mais ce sont les fichiers et programmes qui sont cachés et j'ai plein de message d'alerte qui s'affichent à l'écran. J'ai utilisé comme dans le post Pre Scan et je vous colle le rapport. J'ai vu également apparaitre sur mon bureau un icone Windows restore et quand j'ouvre l'emplacement du fichier pour supprimer le programme je ne trouve pas son nom. Merci de votre aide.
        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan 1.0.0.28 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
        ¤ XP | Vista | Seven - 32/64 ¤
        Mis à jour le 12/04/2011 | 23.00 par g3n-h@ckm@n
        Utilisateur : User (Administrateurs)
        Ordinateur : PC-DE-USER
        Système d'exploitation : Windows Vista (TM) Home Premium (32 bits)
        Architecture OS : X86
        Internet Explorer : 8.0.6001.19019
        Mozilla Firefox : 3.6.16 (fr)
        Scan : 11:37:29 | 13/04/2011
        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
        [HKLM\..\..\Winlogon] | Shell -> Aucune modification : explorer.exe -> explorer.exe
        [HKLM\..\..\Winlogon] | AutoRestartShell -> Aucune modification : 1 -> 1
        [HKLM\..\..\Winlogon] | userinit -> Aucune modification : C:\Windows\system32\userinit.exe, -> C:\Windows\system32\userinit.exe,
        [HKLM\..\..\Winlogon] | PowerDownAfterShutdown -> Modification apportée : 0 -> 1
        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Associations ¤¤¤¤¤¤¤¤¤¤¤¤¤¤
        [.exe] : exefile
        [exefile | command] : "%1" %*
        [.com] : comfile
        [comfile | command] : "%1" %*
        [.scr] : scrfile
        [scrfile | command] : "%1" /S
        [.bat] : batfile
        [batfile | command] : "%1" %*
        [.cmd] : cmdfile
        [cmdfile | command] : "%1" %*
        [.pif] : piffile
        [piffile | command] : "%1" %*
        ¤
        [Firefox | Command] | @ -> Modification apportée : C:\Program Files\Mozilla Firefox\firefox.exe -> "C:\Program Files\Mozilla Firefox\Firefox.exe"
        [Firefox - Safemode | Command] | @ -> Aucune modification : "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode -> "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
        [IE | Command] | @ -> Modification apportée : C:\Program Files\Internet Explorer\iexplore.exe -> "C:\Program Files\Internet Explorer\iexplore.exe"
        [Applications | IE | Command] | @ -> Aucune modification : "C:\Program Files\Internet Explorer\iexplore.exe" %1 -> "C:\Program Files\Internet Explorer\iexplore.exe" %1
        [Chrome | Command] | @ -> Aucune modification : "C:\Program Files\Google\Chrome\Application\chrome.exe" -> "C:\Program Files\Google\Chrome\Application\chrome.exe"
        [Safari | Command] | @ -> Aucune modification : "C:\Program Files\Safari\Safari.exe" -> "C:\Program Files\Safari\Safari.exe"
        ¤
        ¤
        ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤
        0
        1. salut ok je continue avec toi

          le rapport n'est pas entier pourquoi?
          0
          1. Bonjour,

            Excusez moi, j'ai mal copié le fichier. Le voici complet :

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan 1.0.0.28 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            ¤ XP | Vista | Seven - 32/64 ¤

            Mis à jour le 12/04/2011 | 23.00 par g3n-h@ckm@n
            Utilisateur : User (Administrateurs)
            Ordinateur : PC-DE-USER

            Système d'exploitation : Windows Vista (TM) Home Premium (32 bits)
            Architecture OS : X86
            Internet Explorer : 8.0.6001.19019
            Mozilla Firefox : 3.6.16 (fr)

            Scan : 11:37:29 | 13/04/2011

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            [HKLM\..\..\Winlogon] | Shell -> Aucune modification : explorer.exe -> explorer.exe
            [HKLM\..\..\Winlogon] | AutoRestartShell -> Aucune modification : 1 -> 1
            [HKLM\..\..\Winlogon] | userinit -> Aucune modification : C:\Windows\system32\userinit.exe, -> C:\Windows\system32\userinit.exe,
            [HKLM\..\..\Winlogon] | PowerDownAfterShutdown -> Modification apportée : 0 -> 1

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Associations ¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            [.exe] : exefile
            [exefile | command] : "%1" %*
            [.com] : comfile
            [comfile | command] : "%1" %*
            [.scr] : scrfile
            [scrfile | command] : "%1" /S
            [.bat] : batfile
            [batfile | command] : "%1" %*
            [.cmd] : cmdfile
            [cmdfile | command] : "%1" %*
            [.pif] : piffile
            [piffile | command] : "%1" %*

            ¤

            [Firefox | Command] | @ -> Modification apportée : C:\Program Files\Mozilla Firefox\firefox.exe -> "C:\Program Files\Mozilla Firefox\Firefox.exe"
            [Firefox - Safemode | Command] | @ -> Aucune modification : "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode -> "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
            [IE | Command] | @ -> Modification apportée : C:\Program Files\Internet Explorer\iexplore.exe -> "C:\Program Files\Internet Explorer\iexplore.exe"
            [Applications | IE | Command] | @ -> Aucune modification : "C:\Program Files\Internet Explorer\iexplore.exe" %1 -> "C:\Program Files\Internet Explorer\iexplore.exe" %1
            [Chrome | Command] | @ -> Aucune modification : "C:\Program Files\Google\Chrome\Application\chrome.exe" -> "C:\Program Files\Google\Chrome\Application\chrome.exe"
            [Safari | Command] | @ -> Aucune modification : "C:\Program Files\Safari\Safari.exe" -> "C:\Program Files\Safari\Safari.exe"

            ¤

            ¤

            ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

            [Ndisuio] | Start -> Aucune modification : 3 -> 3
            [lmhosts] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [LanmanWorkstation] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [LanmanServer] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [agp440] | Start -> Modification apportée : 3 -> 2 : Service Redemarré
            [Bits] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [CryptSvc] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [EapHost] | Start -> Modification apportée : 3 -> 2 : Service Redemarré
            [Wlansvc] | Start -> Modification apportée : 3 -> 2 : Service Redemarré
            [SharedAccess] | Start -> Modification apportée : 4 -> 2 : Service Redemarré
            [windefend] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [wuauserv] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [WerSvc] | Start -> Aucune modification : 2 -> 2 : Service Actif
            [wscsvc] | Start -> Aucune modification : 2 -> 2 : Service Actif

            ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

            [HKCU | Main] | Start Page -> Modification apportée : http://go.microsoft.com/fwlink/?LinkId=69157 -> http://www.google.com/
            [HKCU | Main] | Local Page -> Aucune Modification : C:\Windows\system32\blank.htm -> C:\Windows\system32\blank.htm
            [HKCU | Main] | Search Page -> Modification apportée : http://go.microsoft.com/fwlink/?LinkId=54896 -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

            [HKLM | Main] | Start Page -> Modification apportée : http://fr.yahoo.com -> http://go.microsoft.com/fwlink/?LinkId=69157
            [HKLM | Main] | Local Page -> Aucune Modification : C:\Windows\System32\blank.htm -> C:\Windows\System32\blank.htm
            [HKLM | Main] | Default_Search_URL -> Aucune Modification : http://go.microsoft.com/fwlink/?LinkId=54896 -> http://go.microsoft.com/fwlink/?LinkId=54896
            [HKLM | Main] | Default_Page_URL -> Modification apportée : http://fr.yahoo.com -> http://go.microsoft.com/fwlink/?LinkId=69157
            [HKLM | Main] | Search Page -> Aucune Modification : http://go.microsoft.com/fwlink/?LinkId=54896 -> http://go.microsoft.com/fwlink/?LinkId=54896

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            C:\ProgramData\43638536.exe -> Processus stoppé
            C:\ProgramData\HDFryVTMFjAtTWN.exe -> Processus stoppé
            C:\Windows\explorer.exe -> Processus stoppé
            C:\Windows\RtHDVCpl.exe -> Processus stoppé

            ¤¤¤¤¤¤¤¤¤¤ Clés supprimées et Fichier mis en quarantaine ¤¤¤¤¤¤¤¤¤¤

            Clé supprimée : [HKCU\..\..\Run] | HDFryVTMFjAtTWN -> C:\ProgramData\HDFryVTMFjAtTWN.exe
            Mis en quarantaine : C:\ProgramData\HDFryVTMFjAtTWN.exe

            ¤¤¤¤¤¤¤¤¤¤ IFEO ¤¤¤¤¤¤¤¤¤¤

            ¤¤¤¤¤¤¤¤¤¤ Mountpoints2 ¤¤¤¤¤¤¤¤¤¤

            Supprimé : [HKCU\..\..\Mountpoints2\{9bb1ba8a-8e61-11df-95da-8b05e26c84f8}] -> command : F:\wubi.exe --cdmenu

            ¤¤¤¤¤¤¤¤¤¤ MBR ¤¤¤¤¤¤¤¤¤¤

            MBRCheck, version 1.2.3

            (c) 2010, AD

            Command-line: -za C:\MBR\MBR.bin

            Windows Version: Windows Vista Home Premium Edition

            Windows Information: Service Pack 2 (build 6002), 32-bit

            Base Board Manufacturer: ASUSTeK Computer INC.

            BIOS Manufacturer: American Megatrends Inc.

            System Manufacturer: System manufacturer

            System Product Name: System Product Name

            Logical Drives Mask: 0x000005dc

            Analysis of file "C:\MBR\MBR.bin":

            Windows 2008 MBR code detected

            Done!
            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            Fin : 11:37:36

            ¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤

            Merci.
            0
            1. continue avec Malekal sur l'autre topic tcha'o
              0