Infection Ramnit / Virus.Win32.Nimnul.a

Résolu
Salut , je crois qu'a trop faire le malin sans antivirus , je me suis fait avoir , et en installant Malware-bytes Anti Malware , il me détecte beaucoup de fichier infectés sous le nom de virus Ramnit , j'espère qu'il n'est pas trop tard , j'ai pas envie de formater , et de tout perdre.

Je fessai un scan tout les soirs avec Rogue Killer et ADW Cleaner mais cela n'as pas suffit , je vous joint le rapport malwarebits.

http://cjoint.com/14au/DHsqqySFoxb.htm

En attente de réponse . Merci d'avance .

12 réponses

Résumé de la discussion

Un utilisateur signale une infection Ramnit après que Malwarebytes détecte de nombreux fichiers infectés, malgré des scans répétés avec RogueKiller et ADWCleaner, et il craint de tout formater. Plusieurs conseils préconisent un balayage complet avec Kaspersky ou des outils dédiés, et de nettoyer ou supprimer les exécutables infectés, le cas échéant en formatant si l’infection est avancée. Des échanges évoquent l’utilisation d’outils comme Kaspersky Removal Tool et l’envoi de rapports, tandis que certains demandent des antivirus gratuits et des méthodes pour évaluer l’étendue de l’infection. En parallèle, l’échange conseille de privilégier des sources fiables pour éviter les fausses détections et orienter correctement les mesures à prendre.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    Fais un scan avec Kaspersky removal tool : https://forum.malekal.com/viewtopic.php?t=33710&start=

    Envoie le rappor sur http://pjjoint.malekal.com
    donne le lien du rapport ici.

    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0
    1. Salut , merci de ta réponse , je traite l'infection avec Malware a la fin de l'analyse , ou je laisse kasperky faire ?
      0
      1. Modérateur
        ne fais rien avec Malwarebytes.
        0
    2. Modérateur
      Les détections Virus.Win32.Nimnul.a, faut réparer ou si ça ne fonctionne pas, supprimer

      18/08/2014 18:15:45 Non traités C:\Program Files\Intel\Media SDK\mfx_mft_h264ve_w7_32.dll Ignoré par l'utilisateur
      18/08/2014 18:15:45 Non réparés: Virus.Win32.Nimnul.a C:\Program Files\Intel\Media SDK\mfx_mft_h264ve_w7_32.dll Ignoré par l'utilisateur
      18/08/2014 18:15:45 Non traités C:\Program Files\Common Files\ATI Technologies\Multimedia\AMDh264Enc32.dll Ignoré par l'utilisateur
      18/08/2014 18:15:45 Non réparés: Virus.Win32.Nimnul.a C:\Program Files\Common Files\ATI Technologies\Multimedia\AMDh264Enc32.dll Ignoré par l'utilisateur
      18/08/2014 18:14:27 Ok C:\Program Files (x86)\Raptr\pyqt4\plugins\imageformats\qico4.dll Objet inchangé (iChecker 3)
      18/08/2014 18:14:27 Ok C:\Windows\SysWOW64\ddraw.dll Objet inchangé (iChecker 3)
      18/08/2014 18:14:27 Ok C:\Windows\SysWOW64\dciman32.dll Objet inchangé (iChecker 3)
      18/08/2014 18:14:27 Ok C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd
      18/08/2014 18:14:27 Ok C:\Program Files (x86)\Raptr\QtGui4.dll Objet inchangé (iChecker 3)
      18/08/2014 18:14:27 Détectés: Virus.Win32.Nimnul.a C:\Program Files\Intel\Media SDK\mfx_mft_h264ve_w7_32.dll

      0
      1. Alors , Kapersky ma réparer 7 fichiers , et supprimer 2 .

        Cependant , il n'y pas de rapport disponible .

        On fait quoi maintenant ?
        0
        1. Modérateur
          tu attends un ou deux jours et tu refais un scan Kaspersky de nettoyage.
          0
        2. D'accord merci .
          0
        3. Faut il refaire un scan du pc complet avec Kapersky ?

          Car MBAM me detecte encore quelque fichiers.
          0
        4. Modérateur
          Malwarebytes détecte encore des Virus.Ramnit ?
          0
        5. Oui , j'ai lancer un scan avec Kapersky sur tout mon disque dur , Il m'as détecté pour le moment 120 menaces.....
          0
      2. Bon bah , kasperky c'est ferme , il avait trouvé 320 menaces..... je sais ce qu'il a fait ...

        Si quelq'un pourrait tout analyser avec un rapport Zhp ou Hijackthis , sa serait gentil.

        Merci d'avance . L'ordi fonctionne normalement mais je suis inquiét du nombre de virus , surtout pour mes affaires personnelles.
        0
        1. Modérateur
          HijackThis & co ne serve à rien dans ton cas.
          Tu as un vrai virus au sens litéral du terme, à savoir il infecte les executables.

          Faut nettoyer/réparer ou supprimer les executables.
          Mais si l'infection est trop avancée, vaut mieux formater.
          0
        2. Tu pourrais m'aider a l'eradiquer totalement ?

          Comment faire pour savoir si elle a trop avancer ?
          0
        3. Salut , j'etais absent ,

          Je choisi quel CD ? Enfin lequel tu me recommande ?
          0
        4. Modérateur
          Kaspersky.
          0
      3. Bon , Kapersky a reussi a reparer les fichier qui étaient infécté du Virus Ramnit.

        Sauf que vu que Kapersky et souvent instable , il plante au bout de 50 % d'analyse a chaque fois , donc je vais essayer avec Dr Web

        Le positif , c'est qu'au lieu d'avoir 150 fichiers detécté avec Ramnit , maintenant j'en ai 25.

        Je te tiens au courant.
        0
        1. Modérateur
          ça roule :)
          0
      4. Bon l'analyse vient de se finir , elle a durée jusqu'à petit matin visiblement .

        4990 fichiers a eradiquer , Le Virus Ramnit a pas toucher le SysWoW64 et le System32

        J'espère que sa vz fonctionner , . Euh sinon les 4990 fichiers ne sont pas que des fichiers ramnit . il y des trojans sous formes de pages HTLM.

        Je le laisse faire , jte file le rapport a la fin
        0
        1. MOUHAHAHAH C'EST BON !

          Tout a été éradiquer au niveau de Windows !

          Kaspersky et Malware Bits me détectent plus aucun Virus Ramnit ou alternative qui a le même effet sur mon Disque Dur C:

          Je vais maintenant passer au Disque dur D: Mais doctor Web a fait une pré analyse et il n'y a que apparemment 5% qu'il soit infecté , je vais quand même le faire.

          Tout mes programmes fonctionnent normalement.

          Par contre il ne m'as pas remis de Journal :/

          Euh , tu pourrais m'aider a voir si ma clé USB a été infecté par Ramnit ?

          Je te remercie pour tout !
          0
          1. Modérateur
            Je ne crois pas que Ramnit infecte les clefs USB (ajout autorun etc).
            Faut juste scanner avec un antivirus pour être sûr que les programmes copiés dedans ne soit pas infecté.

            Aussi mets bien un antivirus actif sur le PC, car tu peux avoir des fichiers non détectés qui sont en réalité infectés... ca eux se voir lors de l'execution, donc faut que l'antivirus le bloque.

            Bref, fais quand meme des scans ces prochains jours.
            0
          2. Alors j'ai fait un Scan complet du C:

            Rien n'as été détecté

            J'ai fait un Scan Complet de mon autre disque dur , tout a été apparement nettoyé , je t'envois le rapport en Cjoint , car Pjoint ne fonctionne pas .....

            Mince le rapport fait 11 mo , trop pour cjoint et Pjoint

            Je te le met directement , ou je te l'upload sur un cloud , ou sur médiafire ?
            0
          3. Modérateur
            zip le.
            0
        2. Modérateur
          Ce sont surtout tes jeux qui ont morflé semble-t-il :

          \ADB\ADB\AdbWinUsbApi.dll - infected with Win32.Rmnet
          E:\ADB\ADB\AdbWinApi.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4124\battle.net.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4124\libEGL.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4124\libcef.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4124\QtNetwork4.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4217\libEGL.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4217\battle.net.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4217\libcef.dll - infected with Win32.Rmnet
          E:\Battle.net\Battle.net.4217\QtNetwork4.dll - infected with Win32.Rmnet
          E:\Battle.net\Logs\Blizzard Updater Log.html\JSTAG_2[2664][1b9bf] - infected with VBS.Rmnet.2
          E:\Battle.net\Logs\Battle.net Install Log.html\JSTAG_1[12f0][1b9bf] - infected with VBS.Rmnet.2
          E:\Battle.net\Logs\Battle.net Install Log.html\JSTag_2[12f5][1b9ba] - infected with Trojan.Inor
          E:\Battle.net\Logs\Blizzard Updater Log.html\JSTag_4[2669][1b9ba] - infected with Trojan.Inor
          E:\FIFA 11\Game\fifa.exe - infected with Win32.Rmnet
          E:\Fifa 14\Game\CardsDLLzf.dll - infected with Win32.Rmnet
          E:\Fifa 14\Game\Core\libeay32.dll - infected with Win32.Rmnet
          E:\Fifa 14\Game\Core\QtCore4.dll - infected with Win32.Rmnet
          E:\Fifa 14\Game\fifa14-SKIDROWGAMES.NET.exe - infected with Win32.Rmnet
          E:\Fifa 14\Game\fifa14-SKIDROWGAMES.NETSrv.exe - infected with Trojan.Packed.20343
          E:\Fifa 14\Game\dlc\dlc_FootballCompEng\dlc\FootballCompEng\FootballCompEngzf.dll - infected with Win32.Rmnet
          E:\Fifa 14\Game\dlc\dlc_powdll\dlc\powdll\powdllzf.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\DLL\components\brwsrcmp.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\DLL\components\browserdirprovider.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\DLL\freebl3.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\DLL\sqlite3.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\Data\components\brwsrcmp.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\Data\components\browserdirprovider.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\DLL\xul.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\Data\defaults\profile\bookmarks.html\JSTAG_1[18c0][1b9bf] - infected with VBS.Rmnet.2
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\Data\defaults\profile\bookmarks.html\JSTag_2[18c5][1b9ba] - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\APB Reloaded\APBGame\Gecko\Data\res\hiddenWindow.html - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\atimgpud.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\cudart.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\libeay32.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\DebuggerAddIn.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\icuuc48.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\NxCooking.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\NxCharacter.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\msvcr71d.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\PhysXCore.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\wrap_oal.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\PhysXLocal\PhysXLoader.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\GFx\PVRTexLib.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\pb\pbag.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\pb\dll\wa001373.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\pb\htm\lc002327.htm - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\pb\htm\la001373.htm - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\pb\htm\ma001373.htm - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\APB Reloaded\Binaries\pb\htm\mc002327.htm - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\Arma 3\ijl15.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Arma 3\BattlEye\BEServer.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Arma 3\Dll\tbb3malloc_bi.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Arma 3\Dll\tbb4malloc_bi.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Arma 3\Launcher\SteamLayer.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call Of Duty Black Ops II\redist\steam_api.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call Of Duty Black Ops II\redist\libnp.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call Of Duty Black Ops II\t6sp.exe - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\gdipp_client_32.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\iw4m.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\libcurld.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\libnp.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\mss32.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\mono-2.0.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Call of Duty Modern Warfare 2\steam_api.dll - infected with Win32.Rmnet
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\FPSChart_Postamble.html - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\FPSChart_Row.html\JSTAG_1[b95][1b9bf] - infected with VBS.Rmnet.2
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\MemoryChart_Preamble.html\JSTAG_1[a04][1b9bf] - infected with VBS.Rmnet.2
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\FPSChart_Row.html\JSTag_2[b9a][1b9ba] - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\MemoryChart_Row.html\JSTAG_1[1fc][1b9bf] - infected with VBS.Rmnet.2
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\MemoryChart_Preamble.html\JSTag_2[a09][1b9ba] - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\MemoryChart_Row.html\JSTag_2[201][1b9ba] - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\MemoryChart_Postamble.html - infected with Trojan.Inor
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\FPSChart_Preamble.html\JSTAG_1[e3b][1b9bf] - infected with VBS.Rmnet.2
          E:\JeuxSteam\SteamApps\common\Hawken\Engine\Stats\FPSChart_Preamble.html\JSTag_2[e40][1b9ba] - infected with Trojan.Inor
          E:\Program Files\Rockstar Games\GTA San Andreas\ogg.dll - infected with Win32.Rmnet
          E:\Program Files\Rockstar Games\GTA San Andreas\vorbis.dll - infected with Win32.Rmnet
          E:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe - infected with Win32.Rmnet
          E:\Program Files\Rockstar Games\GTA San Andreas\eax.dll - infected with Win32.Rmnet
          E:\Program Files\Rockstar Games\GTA San Andreas\vorbisFile.dll - infected with Win32.Rmnet
          E:\REX Essential Plus Overdrive\WxTheme\BGLC.exe - infected with Win32.Rmnet
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\LolClient.exe - infected with Win32.Rmnet
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\Adobe AIR\Versions\1.0\Resources\CaptiveAppEntry.exe - infected with Win32.Rmnet
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\assets\htmlTemplates\child.html\JSTAG_2[6a9][1b9bf] - infected with VBS.Rmnet.2
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\assets\htmlTemplates\parentFrame.html\JSTAG_2[8db][1b9bf] - infected with VBS.Rmnet.2
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\assets\htmlTemplates\store\storeClosedTemplate.html\JSTAG_2[220][1b9bf] - infected with VBS.Rmnet.2
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\assets\htmlTemplates\child.html\JSTag_3[6ae][1b9ba] - infected with Trojan.Inor
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\assets\htmlTemplates\parentFrame.html\JSTag_3[8e0][1b9ba] - infected with Trojan.Inor
          E:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.94\deploy\assets\htmlTemplates\store\storeClosedTemplate.html\JSTag_3[225][1b9ba] - infected with Trojan.Inor
          E:\Riot Games\League of Legends\RADS\projects\lol_game_client\releases\0.0.0.207\deploy\launcher.maestro.dll - infected with Win32.Rmnet
          E:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.17\deploy\launcher.maestro.dll - infected with Win32.Rmnet
          E:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe - infected with Win32.Rmnet
          E:\StarCraft II\Logs\StarCraft II Install Log.html\JSTAG_1[1f7a][1b9bf] - infected with VBS.Rmnet.2
          E:\StarCraft II\Logs\Blizzard Updater Log.html\JSTAG_1[1a58][1b9bf] - infected with VBS.Rmnet.2
          E:\StarCraft II\Logs\StarCraft II Install Log.html\JSTag_2[1f7f][1b9ba] - infected with Trojan.Inor
          E:\StarCraft II\Logs\Blizzard Updater Log.html\JSTag_2[1a5d][1b9ba] - infected with Trojan.Inor
          E:\StarCraft II\Support\ErrorReporter.exe - infected with Win32.Rmnet
          E:\StarCraft II\Support\fmodex_4_28_08.dll - infected with Win32.Rmnet
          E:\StarCraft II\Support\fmodex_4_28_09.dll - infected with Win32.Rmnet
          E:\StarCraft II\Support\fmodex_4_40_06.dll - infected with Win32.Rmnet
          E:\StarCraft II\Support\fmodex_4_40_07.dll - infected with Win32.Rmnet
          E:\StarCraft II\Support\icuuc44.dll - infected with Win32.Rmnet
          E:\Starfriends\MPQEditor.exe - infected with Win32.Rmnet
          E:\Starfriends\StarFriend_Client.exe - infected with Win32.Rmnet
          E:\Télechargement\Call of Duty 4 (Multi-Online) by Team UsToWs\CoD4_Keygen (FFF TEAM).exe - infected with Win32.Rmnet
          E:\Télechargement\Office Professional Plus 2013 FR RTM x86 et x64 [MSDN]\fr_office_professional_plus_2013_x86_dvd_1134001\lisezmoi.htm\JSTAG_1[29e][1b9bf] - infected with VBS.Rmnet.2
          E:\Télechargement\Office Professional Plus 2013 FR RTM x86 et x64 [MSDN]\fr_office_professional_plus_2013_x86_dvd_1134001\lisezmoi.htm\JSTag_2[2a3][1b9ba] - infected with Trojan.Inor
          E:\Télechargement\Toolkit 2.4.9 (CODYXQ4)\UtxEurV15\UtxPatch.exe - infected with Win32.Rmnet
          E:\Télechargement\[FSX] FS Passenger\Crack\FSPassenger_FSX.exe - infected with Win32.Rmnet

          0
          1. Ouai j'ai vu sa aussi.

            J'ai refais une Analyse compléte , rien a été trouvé .

            Merci pour tout monsieur.

            A tu un bon antivirus gratuit a me conseiller ?

            Si oui , merci .
            0
            1. Modérateur
              En gratuit Avast!
              En payant, Kaspersky, NOD32 ou BitDefender
              0
            2. D'accord , Je prend note
              Merci pour tout mon bon monsieur

              Passez une bonne fin de journée.
              0
            3. Modérateur
              à toi aussi :)

              Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html
              0
          2. Salut!! quelques fois quand je tombe sur des ordi virussé à fond, j'utilise combofix!! Utilitaire gratuit!! Après je fais un check disk ( CHKDSK) et cela stabilise le fonctionnement de l'ordinateur quelque soit son niveau d'infection (je pense bien )!!
            -1
            1. Modérateur
              Aucun interêt dans son cas.
              0