Trojan.ransom impossible à supprimer

Résolu
Bonjour, j'ai un problème détecté lors d'analyses effectuées par malwarebytes anti-malware et dont je n'arrive pas à me débarrasser; l'analyse me répète qu' il y un problème détecté "trojan.ransom" que j'ai tenté de supprimer par un redémarrage en mode sans échec avec annulation du point de restauration de sauvegarde mais c'est un échec: je viens de refaire une analyse et le problème demeure..... Merci d'avance pour l'aide que vous pourrez m'apporter afin de supprimer ce problème qui parasite mon PC.

7 réponses

  1. Bonsoir

    [*] Télécharger sur le bureau https://www.luanagames.com/index.fr.html (by tigzy)
    [*] Quitter tous les programmes
    [*] Lancer RogueKiller.exe.
    [*] Attendre que le Prescan ait fini ...
    [*] Cliquer sur Scan. Cliquer sur Rapport et copier coller le contenu du rapport

    @+
    2
    1. Merci Guillaume 5188, voici le rapport:
      RogueKiller V7.6.1 [28/06/2012] par Tigzy
      mail: tigzyRK<at>gmail<dot>com
      Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
      Blog: http://tigzyrk.blogspot.com

      Systeme d'exploitation: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
      Demarrage : Mode normal
      Utilisateur: lydia et stephan [Droits d'admin]
      Mode: Recherche -- Date: 30/06/2012 23:37:49

      ¤¤¤ Processus malicieux: 0 ¤¤¤

      ¤¤¤ Entrees de registre: 4 ¤¤¤
      [SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\LYDIAE~1\LOCALS~1\Temp\msujoawn.com) -> FOUND
      [SUSP PATH] HKUS\S-1-5-21-2727739297-393953247-627550358-1000[...]\Windows : Load (C:\Users\LYDIAE~1\LOCALS~1\Temp\msujoawn.com) -> FOUND
      [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
      [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

      ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

      ¤¤¤ Driver: [NON CHARGE] ¤¤¤

      ¤¤¤ Infection : ¤¤¤

      ¤¤¤ Fichier HOSTS: ¤¤¤
      127.0.0.1 www.007guard.com
      127.0.0.1 007guard.com
      127.0.0.1 008i.com
      127.0.0.1 www.008k.com
      127.0.0.1 008k.com
      127.0.0.1 www.00hq.com
      127.0.0.1 00hq.com
      127.0.0.1 010402.com
      127.0.0.1 www.032439.com
      127.0.0.1 032439.com
      127.0.0.1 www.0scan.com
      127.0.0.1 0scan.com
      127.0.0.1 1000gratisproben.com
      127.0.0.1 www.1000gratisproben.com
      127.0.0.1 1001namen.com
      127.0.0.1 www.1001namen.com
      127.0.0.1 100888290cs.com
      127.0.0.1 www.100888290cs.com
      127.0.0.1 www.100sexlinks.com
      127.0.0.1 100sexlinks.com
      [...]

      ¤¤¤ MBR Verif: ¤¤¤

      +++++ PhysicalDrive0: WDC WD6400AAKS-65A7B2 ATA Device +++++
      --- User ---
      [MBR] 75b36a996cfef6d3091d94175cf4502f
      [BSP] 7d34f083563532ee8e9143cb45805c12 : Windows Vista/7 MBR Code
      Partition table:
      0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
      1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 597610 Mo
      2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1224112128 | Size: 12767 Mo
      User = LL1 ... OK!
      User = LL2 ... OK!

      Termine : << RKreport[1].txt >>
      RKreport[1].txt
      0
      1. Re

        Relance Roguekiller option suppression et Host RAZ

        Poste moi ces deux rapports
        Merci

        à+
        0
        1. Voilà:
          RogueKiller V7.6.1 [28/06/2012] par Tigzy
          mail: tigzyRK<at>gmail<dot>com
          Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
          Blog: http://tigzyrk.blogspot.com

          Systeme d'exploitation: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
          Demarrage : Mode normal
          Utilisateur: lydia et stephan [Droits d'admin]
          Mode: HOSTS RAZ -- Date: 30/06/2012 23:47:46

          ¤¤¤ Processus malicieux: 0 ¤¤¤

          ¤¤¤ Driver: [NON CHARGE] ¤¤¤

          ¤¤¤ Fichier HOSTS: ¤¤¤
          127.0.0.1 www.007guard.com
          127.0.0.1 007guard.com
          127.0.0.1 008i.com
          127.0.0.1 www.008k.com
          127.0.0.1 008k.com
          127.0.0.1 www.00hq.com
          127.0.0.1 00hq.com
          127.0.0.1 010402.com
          127.0.0.1 www.032439.com
          127.0.0.1 032439.com
          127.0.0.1 www.0scan.com
          127.0.0.1 0scan.com
          127.0.0.1 1000gratisproben.com
          127.0.0.1 www.1000gratisproben.com
          127.0.0.1 1001namen.com
          127.0.0.1 www.1001namen.com
          127.0.0.1 100888290cs.com
          127.0.0.1 www.100888290cs.com
          127.0.0.1 www.100sexlinks.com
          127.0.0.1 100sexlinks.com
          [...]

          ¤¤¤ Nouveau fichier HOSTS: ¤¤¤

          Termine : << RKreport[4].txt >>
          RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt
          0
          1. et le rapport N°3 ???
            0
        2. Oups! Désolée.... Le voilà:
          RogueKiller V7.6.1 [28/06/2012] par Tigzy
          mail: tigzyRK<at>gmail<dot>com
          Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
          Blog: http://tigzyrk.blogspot.com

          Systeme d'exploitation: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
          Demarrage : Mode normal
          Utilisateur: lydia et stephan [Droits d'admin]
          Mode: Suppression -- Date: 30/06/2012 23:47:39

          ¤¤¤ Processus malicieux: 0 ¤¤¤

          ¤¤¤ Entrees de registre: 3 ¤¤¤
          [SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\LYDIAE~1\LOCALS~1\Temp\msujoawn.com) -> DELETED
          [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
          [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

          ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

          ¤¤¤ Driver: [NON CHARGE] ¤¤¤

          ¤¤¤ Infection : ¤¤¤

          ¤¤¤ Fichier HOSTS: ¤¤¤
          127.0.0.1 www.007guard.com
          127.0.0.1 007guard.com
          127.0.0.1 008i.com
          127.0.0.1 www.008k.com
          127.0.0.1 008k.com
          127.0.0.1 www.00hq.com
          127.0.0.1 00hq.com
          127.0.0.1 010402.com
          127.0.0.1 www.032439.com
          127.0.0.1 032439.com
          127.0.0.1 www.0scan.com
          127.0.0.1 0scan.com
          127.0.0.1 1000gratisproben.com
          127.0.0.1 www.1000gratisproben.com
          127.0.0.1 1001namen.com
          127.0.0.1 www.1001namen.com
          127.0.0.1 100888290cs.com
          127.0.0.1 www.100888290cs.com
          127.0.0.1 www.100sexlinks.com
          127.0.0.1 100sexlinks.com
          [...]

          ¤¤¤ MBR Verif: ¤¤¤

          +++++ PhysicalDrive0: WDC WD6400AAKS-65A7B2 ATA Device +++++
          --- User ---
          [MBR] 75b36a996cfef6d3091d94175cf4502f
          [BSP] 7d34f083563532ee8e9143cb45805c12 : Windows Vista/7 MBR Code
          Partition table:
          0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
          1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 597610 Mo
          2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1224112128 | Size: 12767 Mo
          User = LL1 ... OK!
          User = LL2 ... OK!

          Termine : << RKreport[3].txt >>
          RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
          0
          1. Re

            Met à jour Malwaresbytes et lance une analyse rapide.
            Poste moi son rapport après suppression

            Merci

            @+
            0
            1. L'analyse n'a révélée aucun élément nuisible mais je n'ai pas eu de rapport à poster... J'imagine que mon problème doit être résolu et je t'en remercie infiniment Guillaume5188 pour ton aide efficace^^
              0