System progressive protection

casanova2700 Messages postés 40 Statut Membre -  
casanova2700 Messages postés 40 Statut Membre -
Bonjour,
Bonjour tout le monde je vous pris de m'aider avec vos conseils mon pc est infecte' avec un malware system progressive protection Jai installé' rogukiller avec le mode sans echec et quand Jai lance'le scan jai clique' sur supprimer je vous copie les rapports qui sont installés'sur le bureau automatiquement je suis navre'e jai ouvert un sujet déjà ouvert ainsi que Jai copie' les rapports sans lien « je ne sais pas comment ca se fait » je vous remercie infiniment de votre aide

7 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Si tu as STOPzilla qui est installé, tu peux le désinstaller, il sert à rien.

    ~~

    Faire un scan OTL pour diagnostiquer les programmes qui tournent et déceler des infections :

    Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

    * Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
    (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

    Dans le cas d'Avast!, ne pas lancer le programme dans la Sandbox (voir lien d'aide ci-dessus).

    * Lance OTL
    * En haut à droite de Analyse rapide, coche "tous les utilisateurs"
    * Sur OTL, sous Personnalisation, copie-colle le script ci-dessous :
    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %temp%\.exe /s
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    %systemroot%\system32\consrv.dll
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    /md5start
    explorer.exe
    winlogon.exe
    wininit.exe
    /md5stop
    HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32 /s
    HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList /s
    CREATERESTOREPOINT
    nslookup www.google.fr /c
    SAVEMBR:0
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs

    * Clique sur le bouton Analyse.
    NE PAS COPIER/COLLER LE RAPPORT ICI - LIRE JUSQU'AU BOUT
    * Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent), donne le ou les liens pjjoint qui pointent vers ces rapports ici dans un nouveau message.

    1
  2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut,

    [*] Télécharger sur le bureau https://www.luanagames.com/index.fr.html (by tigzy)
    [*] Quitter tous les programmes
    [*] Lancer RogueKiller.exe.
    [*] Attendre que le Prescan ait fini ...
    [*] Lance un scan afin de débloquer le bouton Suppression à droite.
    [*] Clic sur Suppression.
    Poste le rapport ici.

    !!! Je répète bien faire Suppression à droite et poster le rapport. !!!

    0
  3. casanova2700 Messages postés 40 Statut Membre 1
     
    salut je vous remercie de votre reponse jai bien suivi linstruction et voila les rapports .
    RogueKiller V8.2.0 [10/22/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : nasih nezha [Admin rights]
    Mode : Scan -- Date : 10/26/2012 10:21:04

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost #***Inserted By STOPzilla***
    127.0.0.1 0websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
    127.0.0.1 600pics.com # ***Inserted By STOPzilla***
    127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
    127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
    127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
    127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla***
    127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
    127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
    127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***
    127.0.0.1 bailefunk.com # ***Inserted By STOPzilla***
    127.0.0.1 barteros.net # ***Inserted By STOPzilla***
    127.0.0.1 best4all.net # ***Inserted By STOPzilla***
    127.0.0.1 besthardcore.net # ***Inserted By STOPzilla***
    127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla***
    127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla***
    127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla***
    127.0.0.1 brazauskas.info # ***Inserted By STOPzilla***
    [...]

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: FUJITSU MHV2160BT PL +++++
    --- User ---
    [MBR] 8ff6a21bb831678155f0de5fe52d37b0
    [BSP] 3bfe4a015da43f138cc67e8ffc2c96a9 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152374 Mo
    3 - [XXXXXX] UNKNOWN (0x88) [VISIBLE] Offset (sectors): 312062625 | Size: 251 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[5].txt >>
    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt

    RogueKiller V8.2.0 [10/22/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : nasih nezha [Admin rights]
    Mode : Remove -- Date : 10/26/2012 10:21:44

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost #***Inserted By STOPzilla***
    127.0.0.1 0websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
    127.0.0.1 600pics.com # ***Inserted By STOPzilla***
    127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
    127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
    127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
    127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla***
    127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
    127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
    127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***
    127.0.0.1 bailefunk.com # ***Inserted By STOPzilla***
    127.0.0.1 barteros.net # ***Inserted By STOPzilla***
    127.0.0.1 best4all.net # ***Inserted By STOPzilla***
    127.0.0.1 besthardcore.net # ***Inserted By STOPzilla***
    127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla***
    127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla***
    127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla***
    127.0.0.1 brazauskas.info # ***Inserted By STOPzilla***
    [...]

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: FUJITSU MHV2160BT PL +++++
    --- User ---
    [MBR] 8ff6a21bb831678155f0de5fe52d37b0
    [BSP] 3bfe4a015da43f138cc67e8ffc2c96a9 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152374 Mo
    3 - [XXXXXX] UNKNOWN (0x88) [VISIBLE] Offset (sectors): 312062625 | Size: 251 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[6].txt >>
    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt ;
    RKreport[6].txt

    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''when there is a will there is a way''''''''''''''''''''''''''''''''''''''
    0
  4. casanova2700 Messages postés 40 Statut Membre 1
     
    je sais pas esque vous avez bien recu la reponse?? avec les messages d'erreurs que je recois jai beaucoup de troubles pour vous repondre
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. casanova2700 Messages postés 40 Statut Membre 1
     
    salut

    RogueKiller V8.2.0 [10/22/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : nasih nezha [Admin rights]
    Mode : Remove -- Date : 10/26/2012 10:21:44

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost #***Inserted By STOPzilla***
    127.0.0.1 0websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
    127.0.0.1 600pics.com # ***Inserted By STOPzilla***
    127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
    127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
    127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
    127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla***
    127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
    127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
    127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***
    127.0.0.1 bailefunk.com # ***Inserted By STOPzilla***
    127.0.0.1 barteros.net # ***Inserted By STOPzilla***
    127.0.0.1 best4all.net # ***Inserted By STOPzilla***
    127.0.0.1 besthardcore.net # ***Inserted By STOPzilla***
    127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla***
    127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla***
    127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla***
    127.0.0.1 brazauskas.info # ***Inserted By STOPzilla***
    [...]

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: FUJITSU MHV2160BT PL +++++
    --- User ---
    [MBR] 8ff6a21bb831678155f0de5fe52d37b0
    [BSP] 3bfe4a015da43f138cc67e8ffc2c96a9 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152374 Mo
    3 - [XXXXXX] UNKNOWN (0x88) [VISIBLE] Offset (sectors): 312062625 | Size: 251 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[6].txt >>
    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt ;
    RKreport[6].txt

    RogueKiller V8.2.0 [10/22/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : nasih nezha [Admin rights]
    Mode : Scan -- Date : 10/26/2012 10:21:04

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost #***Inserted By STOPzilla***
    127.0.0.1 0websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
    127.0.0.1 600pics.com # ***Inserted By STOPzilla***
    127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
    127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
    127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
    127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla***
    127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
    127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
    127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***
    127.0.0.1 bailefunk.com # ***Inserted By STOPzilla***
    127.0.0.1 barteros.net # ***Inserted By STOPzilla***
    127.0.0.1 best4all.net # ***Inserted By STOPzilla***
    127.0.0.1 besthardcore.net # ***Inserted By STOPzilla***
    127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla***
    127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla***
    127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla***
    127.0.0.1 brazauskas.info # ***Inserted By STOPzilla***
    [...]

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: FUJITSU MHV2160BT PL +++++
    --- User ---
    [MBR] 8ff6a21bb831678155f0de5fe52d37b0
    [BSP] 3bfe4a015da43f138cc67e8ffc2c96a9 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152374 Mo
    3 - [XXXXXX] UNKNOWN (0x88) [VISIBLE] Offset (sectors): 312062625 | Size: 251 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[5].txt >>
    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt
    0
  7. casanova2700 Messages postés 40 Statut Membre 1
     
    bonjour

    :( je n'ais pas pu l'exucuter pourtant je n'est pas le programme avast !
    0
  8. casanova2700 Messages postés 40 Statut Membre 1
     
    bonjour ,

    apres avoir essaye' plusieurs fois je pense que OTL ne va pas marcher je suis maintenant entrain de demarer MBAM mais c'est encore pire j'attend tjrs votre intervention et j'espere bien avoir une solution concise et efficase

    je vous en serais gree'.
    0