Chui infecté - Page 2

Résolu
Précédent
  • 1
  • 2
  1. massassi zunukananani Messages postés 23 Statut Membre 2
     
    le rapport de ZHPdiag: http://www.cijoint.fr/cjlink.php?file=cj201104/cijPqGtqwa.txt
    0
  2. massassi zunukananani Messages postés 23 Statut Membre 2
     
    OK je vois. tout d'abord pour les mises a jour. la mise a jour automatique dans panneau de configuration est -ce une bonne chose? ou faudrait il que je les téléchargent moi même?
    0
  3. Smart91 Messages postés 30146 Statut Contributeur sécurité 2 331
     
    "OK je vois. tout d'abord pour les mises a jour. la mise a jour automatique dans panneau de configuration est -ce une bonne chose?"
    La réponse est OUI.

    Et si tu ne les as pas déjà fait il faut le faire manuellement

    Smart
    0
  4. massassi zunukananani Messages postés 23 Statut Membre 2
     
    bonsoir, excusez moi de ne répondre que maintenant, mais j'attendais d'abord de faire toutes les mises à jour. mais il y a toujours le problème qui persiste malheureusement; car après avoir changer mon pack en SP3 et IEE en IE8 et faits toutes les mises à jours que le système m'a proposé; j'ai voulu télécharger avast6 comme vous me l'aviez indiquez avec le lien. mais malheureusement une fois que j'ai cliqué sur le lien la fenêtre c'est automatiquement refermé et j'ai insisté mais rien n'y fait.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Smart91 Messages postés 30146 Statut Contributeur sécurité 2 331
     
    Fais un scan complet avec MBAM et psote le rapport

    Smart
    0
  7. massassi zunukananani Messages postés 23 Statut Membre 2
     
    bonsoir, cette fois ci le téléchargement de MBAM c'est bien passé et j'ai pu faire le scan complet comme vous me l'aviez indiqué. et voila ce que donne le rapport:

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Version de la base de données: 6385

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    17/04/2011 22:00:35
    mbam-log-2011-04-17 (22-00-35).txt

    Type d'examen: Examen complet (C:\|)
    Elément(s) analysé(s): 213136
    Temps écoulé: 1 heure(s), 15 minute(s), 17 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 1
    Clé(s) du Registre infectée(s): 1
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 65

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    c:\WINDOWS\system32\ddefabbedb.dll (Worm.AutoRun) -> Delete on reboot.

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddefabbedb (Worm.AutoRun) -> Delete on reboot.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    c:\WINDOWS\system32\ddefabbedb.dll (Worm.AutoRun) -> Delete on reboot.
    c:\system volume information\_restore{ca5ee3c7-9fa7-4f4e-ac70-3aff69ce6f3e}\RP185\A0204464.dll (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\system volume information\_restore{ca5ee3c7-9fa7-4f4e-ac70-3aff69ce6f3e}\RP185\A0204465.dll (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\091d778ea63ee829d5d43d80208819b9.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\117a6f7bd85a1de99a25882bf2e8d962.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\148b4fe26e65179454cacb665504ed5b.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\af671e6b8eb7716385217f0c66b9fc1b.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\b075c938769f8c6e11f1eb074691435a.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\b12258c3cb25f5220e310c5306f190e6.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\b45a95565d4ccc7d8c86ff01f3dad56c.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\bf2650e8ded4cdbf55621ea9799651c9.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\c48f3f5323a6e09dba80169f4d90c42f.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\c86e696c0d9b451b1bab175bb0920f4f.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\d2654127c50fae4f5b280e2d534e4dec.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\ee8fcdcb448e93dd1ede0022ced23c5b.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\f2ce1484c0a4fae3abae358cb2afe1bc.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\f598dd1318333a3659c351835179720f.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\f5d2473035e6b5bce2d9b285fb13ab24.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\f5f681ec710aedcb89c360daf5f70330.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\f61c942334e813827885f0971a234d4b.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\fdc8f6a782024401cad53519dfc24d5b.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\71fc89081847506c15ba15d7aaaa2471.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\903b11d8ccfd2a392161c74d1af4cc46.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\e3f42ad27fe45a2e379a3745fe443c6f.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\d9cc3c54e67bd9c4a291aee592515ef1.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\92f3676469002a75933c3bc8f9a28a71.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\95938e033169b57deb28e42b95b73127.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\97e9bb883d727d266d69bdf6724f1e6f.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\99c391f021939834fec28bcf29ccbfb3.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\9a13efe1c6fc5449ec73b300f3cafd8e.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\a640c70e2289fc24060cb46987612dfc.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\acafe660e1025e2d91c9d494058c31cb.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\44d401675ac943dbb839f67e28693d94.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\4744a2ec39b87a2013dbc94fa3bec18e.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\4b9b5c66eeca2d3edc4ba5e7d91f90d9.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\4f062605ca355b76211487655eef80ce.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\5215b715dfe6cd3535850ae9365153e1.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\53f648346fbb7a64581d54be45292ec6.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\540fca954dda95282cfed4b812c8ff58.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\65be0fd5c1c239192f3125e075fb1d5b.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\6d83ec6b9e9fbdbf052369425e24ce09.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\701dd6b1e6ae33565088eb2e9e1ab9e5.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\729f019fab4d1f7c8e574ad4ac97556f.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\74325080d12ac85877b0b45294699aeb.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\750fdf13c78ddb55e1606ff753a3c583.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\801134e4477b237a045ab54f1cc9320c.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\813b24eb13d7008c164a0a09ddff6522.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\83dd590de441f2b7219bede1692a1e96.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\856c0967ef74803347d0ce2191436135.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\8bf5e8de882dd071fa8e6c913cd14f31.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\8c23df3726bc946e87f06aa8f6888c5c.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\185f858cade76e8a0c34d1473bc81c92.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\18e6058740c70a8b83e0a90c461db1c3.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\1938ce60375766ecec71b4583073db8e.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\1e9065ab48ccc054e5674df25d282784.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\20a71907988091d8506074b7fd979611.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\26934411ca475d0ea2973ab5252532a4.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\28b79e9df79c0e4f6bcb029fc64223b8.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\2a8e2a2c3efa94b7ce9fb4173bb53bc3.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\3759fb94010e028b1b32012f7accfaee.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\386a4cb86f3e5ff8a06cc81e21f2403a.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\3995095d0511f646e736902b9ded6026.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\e621743b48dc6d9675ec65ba803524c2.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\e792f21ebe102a2e4d9fa2577d4ecfd9.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\ec813d75f42dd25aa214a9bf8b98ba88.tmp (Worm.AutoRun) -> Quarantined and deleted successfully.
    0
  8. massassi zunukananani Messages postés 23 Statut Membre 2
     
    j'ai télécharger avast. donc je suppose que je peux poursuivre vos instructions à savoir: Mise à jour Adobe Reader 10.0.1
    Optimisation:
    Désinstallation des outils.........
    0
  9. Smart91 Messages postés 30146 Statut Contributeur sécurité 2 331
     
    Tout à fait. fais ls suite

    Smart
    0
  10. massassi zunukananani Messages postés 23 Statut Membre 2
     
    Excusez de ne répondre que maintenant mais les mises à jours m'ont pris beaucoup trop de temps, et ça va vallu la peine car maintenant tous mes logiciels sont à jours. voici les rapports que j'ai obtenus :

    Rapport de ZHPFix 1.12.3277 par Nicolas Coolman, Update du 20/04/2011
    Fichier d'export Registre :
    Run by Tonton at 20/04/2011 23:24:12
    Windows XP Professional Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

    ========== Clé(s) du Registre ==========
    O23 - Service: (mchInjDrv) - Clé orpheline => Clé non supprimée

    ========== Valeur(s) du Registre ==========
    O4 - HKLM\..\Run: [NeroFilterCheck] . (.Ahead Software Gmbh - NeroCheck.) -- C:\WINDOWS\system32\NeroCheck.exe => Valeur absente
    O4 - HKLM\..\Run: [RemoteControl] . (.Cyberlink Corp. - PowerDVD RC Service.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe => Valeur absente
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe => Valeur absente
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe => Valeur absente

    ========== Elément(s) de donnée du Registre ==========
    CTFDisabled => Donnée supprimée avec succès

    ========== Récapitulatif ==========
    1 : Clé(s) du Registre
    4 : Valeur(s) du Registre
    1 : Elément(s) de donnée du Registre

    End of the scan

    RAPPORT AVEC DELFIX

    # DelFix v7.7B - Rapport créé le 20/04/2011 à 23:29
    # Mis à jour le 15/04/11 à 19h30 par Xplode
    # Système d'exploitation : Microsoft Windows XP (32 bits) [version 5.1.2600] Service Pack 3
    # Nom d'utilisateur : Tonton - FG-F73FFA10D8A4 (Administrateur)
    # Exécuté depuis : C:\Documents and Settings\Tonton\Bureau\DelFix.exe
    # Option [Suppression]

    ~~~~~~ Dossier(s) ~~~~~~

    Non supprimé (1) : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP

    ~~~~~~ Fichier(s) ~~~~~~

    Supprimé : C:\ZHPExportRegistry-20-04-2011-23-24-12.txt
    Supprimé : C:\Documents and Settings\Tonton\Bureau\ZHPFixReport.txt
    Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk

    ~~~~~~ Registre ~~~~~~

    ~~~~~~ Autre ~~~~~~

    ########## EOF - "C:\DelFixSuppr.txt" - [856 octets] ##########
    0
  11. Smart91 Messages postés 30146 Statut Contributeur sécurité 2 331
     
    C'es bon continue. Bon courage

    Smart
    0
Précédent
  • 1
  • 2